CVE-2026-48707 | InstantSoft icms2 up to 2.18.1 File Upload system/core/uploader.php server-side request forgery
A vulnerability labeled as problematic has been found in InstantSoft icms2 up to 2.18.1. This impacts an unknown function of the file system/core/uploader.php of the component File Upload. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-48707. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More