Product
instantcms
23 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-28281
CVE-2025-59055
CVE-2013-10051
CVE-2024-50348
CVE-2024-31213
CVE-2024-31212
CVE-2023-4928
CVE-2023-4879
CVE-2023-4878
CVE-2023-4704
CVE-2023-4655
CVE-2023-4654
CVE-2023-4653
CVE-2023-4652
CVE-2023-4651
CVE-2023-4650
CVE-2023-4649
CVE-2023-4381
CVE-2023-4189
CVE-2023-4188
CVE-2023-4187
CVE-2018-14382
CVE-2013-6839
< 2.18.1
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which a
<= 2.17.3
InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in Instan
<= 1.6.0
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the sear
< 2.16.3
InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input
< 2.16.2
InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2
all versions
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which
< 2.16.1
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
< 2.16.1
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
< 2.16.1
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
< 2.16.1
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
< 2.16.1
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.
< 2.16.1
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
< 2.16.1
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
< 2.16.1
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
all versions
InstantCMS 2.10.1 has /redirect?url= XSS.
<= 1.10.3
SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands