CVE-2026-108567 | InstantSoft icms2 up to 2.18.2 Image system/fields/image.php files_delete_file size path traversal
A vulnerability has been found in InstantSoft icms2 up to 2.18.2 and classified as problematic. Impacted is the function files_delete_file of the file system/fields/image.php of the component Image Handler. Performing a manipulation of the argument size results in path traversal.
This vulnerability was named CVE-2026-108567. The attack may be initiated remotely. In addition, an exploit is available.
It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More