PatchSiren

Poesis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Poesis CVE published 2026-08-05

CVE-2026-18856

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T01:16:44.757Z and has not been modified since then. The vulnerability affects Poesis Rhymix CMS up to version 2.1.33, specifically in the procImporterAdminCheckXmlFile function of the modules/importer/importer.admin.controller.php file. This server-side request forgery vulnerability allows remote [truncated]