Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Instantcms

First CVE: Jul 18, 2018Active for: 8 yearsTotal CVEs: 22
33.7
VTI Score
Medium

InstantCMS is a content management system with a modestly sized but notably recurrent vulnerability footprint concentrated in its core product line. The exposure recurs across input-handling and request-processing weaknesses, including cross-site scripting, SQL injection, server-side request forgery, cross-site request forgery, and external configuration control, reflecting characteristic risks in web-based CMS platforms. A meaningful share of the vendor's vulnerabilities reach serious severity, though the overall profile is driven by the durable patterns in application-layer attack surface rather than by exploit or in-the-wild activity. Defenders should treat InstantCMS instances as requiring consistent input-validation and web-security hygiene, particularly where user-facing content generation or administrative controls are exposed. Current severity, exploitation status, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Instantcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 18, 2018
8 years ago
Most Recent CVE
Mar 10, 2026
136 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-10051CRITICAL
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input
Aug 1, 20259.846NOYES
CVE-2023-4188CRITICAL
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
Aug 5, 20239.127NONO
CVE-2025-59055HIGH
InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and including 2.17.3 allows authenticat
Sep 11, 20257.224NONO
CVE-2026-28281HIGH
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to user
Mar 10, 20267.123NONO
CVE-2023-4928HIGH
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
Sep 13, 20237.222NONO
CVE-2024-31212HIGH
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cau
Apr 4, 20247.221NONO
CVE-2018-14382MEDIUM
InstantCMS 2.10.1 has /redirect?url= XSS.
Jul 18, 20186.121NONO
CVE-2023-4655MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
Aug 31, 20236.120NONO
CVE-2023-4879MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
Sep 10, 20234.819NONO
CVE-2023-4878MEDIUM
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
Sep 10, 20235.419NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
68%
18%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (50.0%)
Unknown0 (0.0%)
Required11 (50.0%)
Privileges Required
Low8 (36.4%)
High9 (40.9%)
None5 (22.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Instantcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Instantcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Instantcms's Products

View all 4 CNAs →

Top CWEs