CVE-2026-48707 | InstantSoft icms2 up to 2.18.1 File Upload system/core/uploader.php server-side request forgery

SecurityVulns

A vulnerability labeled as problematic has been found in InstantSoft icms2 up to 2.18.1. This impacts an unknown function of the file system/core/uploader.php of the component File Upload. Such manipulation leads to server-side request forgery.

This vulnerability is documented as CVE-2026-48707. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More