CVE-2026-1978: KALYAN02 Nanocms
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.
Affected products
- KALYAN02 Nanocms: up to and including 0.4
Published 2026-02-06. Last modified 2026-06-17.