CVE-2026-18856 | Poesis Rhymix CMS up to 2.1.33 Data Import importer.admin.controller.php procImporterAdminCheckXmlFile filename server-side request forgery (KVE-2026-0992)
A vulnerability classified as critical has been found in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery.
This vulnerability is tracked as CVE-2026-18856. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More