Concrete CMS is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block (CVE-2026-7881) | HOL Guard CVE