CVE-2026-1978
MEDIUMkalyan02 NanoCMS <0.4 - Info Disclosure
Title source: llmDescription
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.
References (5)
Scores
CVSS v3
5.3
EPSS
0.0004
EPSS Percentile
11.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-425
Status
published
Affected Products (1)
kalyan02/nanocms
< 0.4
Timeline
Published
Feb 06, 2026
Tracked Since
Feb 18, 2026