InstantCMS is a content management system with a modestly sized but notably recurrent vulnerability footprint concentrated in its core product line. The exposure recurs across input-handling and request-processing weaknesses, including cross-site scripting, SQL injection, server-side request forgery, cross-site request forgery, and external configuration control, reflecting characteristic risks in web-based CMS platforms. A meaningful share of the vendor's vulnerabilities reach serious severity, though the overall profile is driven by the durable patterns in application-layer attack surface rather than by exploit or in-the-wild activity. Defenders should treat InstantCMS instances as requiring consistent input-validation and web-security hygiene, particularly where user-facing content generation or administrative controls are exposed. Current severity, exploitation status, and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Instantcms over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-10051CRITICAL A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input | Aug 1, 2025 | 9.8 | 46 | NO | YES |
CVE-2023-4188CRITICAL SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | Aug 5, 2023 | 9.1 | 27 | NO | NO |
CVE-2025-59055HIGH InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and including 2.17.3 allows authenticat | Sep 11, 2025 | 7.2 | 24 | NO | NO |
CVE-2026-28281HIGH InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to user | Mar 10, 2026 | 7.1 | 23 | NO | NO |
CVE-2023-4928HIGH SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | Sep 13, 2023 | 7.2 | 22 | NO | NO |
CVE-2024-31212HIGH InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cau | Apr 4, 2024 | 7.2 | 21 | NO | NO |
CVE-2018-14382MEDIUM InstantCMS 2.10.1 has /redirect?url= XSS. | Jul 18, 2018 | 6.1 | 21 | NO | NO |
CVE-2023-4655MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. | Aug 31, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-4879MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. | Sep 10, 2023 | 4.8 | 19 | NO | NO |
CVE-2023-4878MEDIUM Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | Sep 10, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Instantcms.
Media articles that mention a CVE ID that affects a product developed by Instantcms — matched by CVE ID, not by vendor name.