MEDIUM 5.5 NVD
CVE-2026-54611
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticat
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.
References
- https://github.com/instantsoft/icms2/commit/44f3a9d04a3207c82cdc756599cbdf084a02858f
- https://github.com/instantsoft/icms2/security/advisories/GHSA-vvgv-h28h-p2m5
- https://github.com/instantsoft/icms2/security/advisories/GHSA-vvgv-h28h-p2m5
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.