CVE-2026-94103

CVE & Vulnerabilities · September 23, 2026

CVE & Vulnerabilities·nvd.nist.gov

NVD has published CVE-2026-94103, a remote code-injection flaw in RooCMS versions up to 1.2.2, 1.3.4, and 1.4RC2. The bug lives in the frontend rendering code's eval() call in site_pagePHP.php, where the content argument isn't sanitized before being executed. A working exploit is already public, and the RooCMS maintainers reportedly haven't responded to the disclosure.

// source: nvd.nist.gov ↗

Back to Blog