CVE-2026-18856
Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component.
| CWE | CWE-918 |
| Vendor | poesis |
| Product | rhymix cms |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for poesis rhymix cms
Be the first to know when new medium vulnerabilities affecting poesis rhymix cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Poesis / Rhymix CMS
2.1.0 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.26 2.1.27 2.1.28 2.1.29 2.1.30 2.1.31 2.1.32 2.1.33
References
vuldb.com: https://vuldb.com/vuln/385868 vuldb.com: https://vuldb.com/vuln/385868/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18856 vuldb.com: https://vuldb.com/submit/858471 github.com: https://github.com/MCzhao2006/Rhymix-SSRF-Report rhymix.org: https://rhymix.org/news/1948042 rhymix.org: https://rhymix.org/files/attach/releases/rhymix-2.1.34.zip