CVE & Vulnerabilities · September 23, 2026
NVD has published CVE-2026-94103, a remote code-injection flaw in RooCMS versions up to 1.2.2, 1.3.4, and 1.4RC2. The bug lives in the frontend rendering code's eval() call in site_pagePHP.php, where the content argument isn't sanitized before being executed. A working exploit is already public, and the RooCMS maintainers reportedly haven't responded to the disclosure.
// source: nvd.nist.gov ↗