Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Instantcms HIGH 7.1
CVE-2026-28281

InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers gra…

Fix: 2.18.1+
Fix from $1,950 2026-03-10
Instantcms HIGH 7.2
CVE-2025-59055

InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and incl…

Fix: after 2.17.3
Fix from $1,950 2025-09-11
Instantcms CRITICAL 9.8
CVE-2013-10051

A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Sp…

Fix: after 1.6.0
Fix from $2,300 2025-08-01
Instantcms MEDIUM 5.4
CVE-2024-50348

InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking …

Fix: 2.16.3+
Fix from $1,600 2024-10-29
Instantcms MEDIUM 5.4
CVE-2024-31213

InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirec…

Fix: 2.16.2+
Fix from $1,600 2024-04-05
Instantcms HIGH 7.2
CVE-2024-31212

InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with ad…

No fix yet
Fix from $1,950 2024-04-04
Icms2 HIGH 7.2
CVE-2023-4928

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.

Fix: 2.16.1+
Fix from $1,950 2023-09-13
Instantcms MEDIUM 5.4
CVE-2023-4878

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

Fix: 2.16.1+
Fix from $1,600 2023-09-10
Instantcms MEDIUM 6.1
CVE-2023-4655

Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.

Fix: 2.16.1+
Fix from $1,600 2023-08-31
Instantcms MEDIUM 5.4
CVE-2023-4652

Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

Fix: 2.16.1+
Fix from $1,600 2023-08-31
Instantcms MEDIUM 5.4
CVE-2023-4649

Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.

Fix: 2.16.1+
Fix from $1,600 2023-08-31
Instantcms MEDIUM 5.4
CVE-2023-4651

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.

Fix: 2.16.1+
Fix from $1,600 2023-08-31
Instantcms CRITICAL 9.1
CVE-2023-4188

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

Fix: 2.16.1+
Fix from $2,300 2023-08-05
Instantcms MEDIUM 6.1
CVE-2018-14382

InstantCMS 2.10.1 has /redirect?url= XSS.

No fix yet
Fix from $1,600 2018-07-18