Junglewise Threat Intelligence

CVE-2026-94103: RooCMS code injection in frontend rendering

CVE-2026-94103 · Severity: medium · CVSS 4.7 · Published 2026-09-21

Executive brief

RooCMS is a content management system used to build and manage websites. A code injection vulnerability in the frontend rendering component allows remote attackers to execute arbitrary code on the server by manipulating content arguments, potentially leading to full server compromise and data theft.

Technical details

A code injection flaw exists in the eval function of roocms/site_pagePHP.php's frontend rendering component. The vulnerability stems from insufficient sanitization of the content parameter, allowing an unauthenticated remote attacker to inject and execute arbitrary PHP code with no user interaction required.

Affected products

  • RooCMS RooCMS up to 1.2.2, 1.3.4, and 1.4RC2

Timeline

  • 2026-09-21: disclosed

References