The CVE-2026-52021 vulnerability in code100xDevs 100xdevs CMS v.1.0 allows a remote attacker to obtain sensitive information via the src/middleware.ts and src/app/api/mobile/search/route.ts components. This issue has a CVSS score of 7.5, indicating high severity. Organizations should review and verify the presence of this CMS version, focusing on the mentioned components for potential sensitive informatio [truncated]
CVE-2026-8890 documents an authentication bypass vulnerability in the code100x CMS Mobile API, published 2026-05-26. The flaw resides in middleware.ts, where the presence of an Auth-Key header—without validation of its value—causes the middleware to skip legitimate identity header generation. Attackers can exploit this by supplying a crafted JSON payload in the 'g' HTTP header, injecting a spoofed user id [truncated]