Instantsoft / Icms2
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48707 | InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning | LOW | 3.1 | Sep 8, 2026 |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | MEDIUM | 5.5 | Sep 8, 2026 |
| CVE-2026-28281 | InstantCMS has Multiple CSRF Vulnerabilities | HIGH | 7.1 | Mar 9, 2026 |
| CVE-2025-59055 | InstantCMS vulnerable to Server-Side Request Forgery via package installer | HIGH | 7.2 | Sep 11, 2025 |
| CVE-2024-50348 | InstantCMS has a Cross Site Scripting Vulnerability | MEDIUM | 5.4 | Oct 29, 2024 |
| CVE-2024-31213 | InstantCMS Open Redirect vulnerability | MEDIUM | 5.4 | Apr 5, 2024 |
| CVE-2024-31212 | SQL injection in index_chart_data action | HIGH | 7.2 | Apr 4, 2024 |
Showing 1 to 7 of 7 CVEs