CVE-2026-108566 | InstantSoft icms2 up to 2.18.2 Private Message index.tpl.php index nickname cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, was found in InstantSoft icms2 up to 2.18.2. This issue affects the function index of the file templates/default/controllers/messages/index.tpl.php of the component Private Message Handler. Such manipulation of the argument nickname leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-108566. The attack can be launched remotely. Moreover, an exploit is present.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More