CVE-2026-108567 | InstantSoft icms2 up to 2.18.2 Image system/fields/image.php files_delete_file size path traversal

SecurityVulns

A vulnerability has been found in InstantSoft icms2 up to 2.18.2 and classified as problematic. Impacted is the function files_delete_file of the file system/fields/image.php of the component Image Handler. Performing a manipulation of the argument size results in path traversal.

This vulnerability was named CVE-2026-108567. The attack may be initiated remotely. In addition, an exploit is available.

It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More