CVE-2026-52021: 100xdevs CMS vulnerability
Published Aug 20, 2026
·Updated
An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components.
Affected Software
1 affected component
100xdevs CMS=1.0
Event History
Aug 20, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which components should be reviewed for exposure?
Review src/middleware.ts and src/app/api/mobile/search/route.ts in code100xDevs 100xdevs CMS v1.0, as these are the components identified as allowing remote sensitive-information disclosure.
2
Does exploitation require local access?
No. The issue is described as exploitable by a remote attacker.