Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CMSMasters Content Composer Allows Malicious File Access
CVE-2026-25326
Summary
A flaw in CMSMasters Content Composer allows attackers to access sensitive files on your website. This could happen if an attacker tricks the system into including a file that shouldn't be loaded, potentially giving them access to confidential data. Update to version 1.4.6 or later to fix this issue.
Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PH...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.
nvd CVSS3.1
7.5
Vulnerability type
CWE-98
Improper Control of Filename for Include
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026