---
id: CVE-2026-94103
title: A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2
summary: >-
  A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This
  impacts the function eval of the file roocms/site_pagePHP.php of the component
  Frontend Rendering. Such manipulation of the argument content leads to code
  injection.…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
product: RooCMS
affected:
  - RooCMS 1.2.0
  - RooCMS 1.2.1
  - RooCMS 1.2.2
  - RooCMS 1.3.0
  - RooCMS 1.3.1
  - RooCMS 1.3.2
  - RooCMS 1.3.3
  - RooCMS 1.3.4
  - RooCMS 1.4RC2
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:17:28.897'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94103'
references:
  - url: 'https://github.com/boyslikesports/202607_vul_dir/blob/main/RooCMS-C1-EN.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94103'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/893004'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408033'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408033/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T15:59:20.814021Z'
epss: 0.00412
epssPercentile: 0.32633
ingestedAt: '2026-09-21T01:29:29.702Z'
---

## Overview

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
