Impact
A flaw in the middleware and mobile search routing modules of the code100xDevs 100xdevs CMS allows a remote attacker to retrieve confidential data without authentication. As a result, attackers could expose protected information that should only be available to privileged users, potentially leading to privacy violations and enabling further exploitation.
Affected Systems
The vulnerability affects code100xDevs 100xdevs CMS version 1.0, released on 2026-04-30. No public patches or workarounds have been issued at the time of this report.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, so its current exploitation likelihood is unclear. However, given that the affected components are exposed via web endpoints, the likely attack vector is remote over HTTP/HTTPS. The absence of an official fix means that any system running the vulnerable CMS version could be susceptible to an undisclosed information‑disclosure attack.
OpenCVE Enrichment