PatchSiren

RooCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW RooCMS CVE published 2026-09-21

CVE-2026-94103

A vulnerability was found in RooCMS up to 1.2.2/1.3.4/1.4RC2 in the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. This leads to code injection. The attack can be launched remotely. The vulnerability impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering in RooCMS up to 1.2.2/1.3.4/1.4RC2, leading to code injection. Defende [truncated]