icms2 vulnerabilities
CVEs whose affected-version data names the icms2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54611Medium· 5.5PoCInstantCMS is a free and open source content management system
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possi…
▾ Twilightinstantsoft · icms2EPSS 0.52%via NVD
CVE-2026-48707Low· 3.1PoCInstantCMS is a free and open source content management system
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "up…
▾ Twilightinstantsoft · icms2EPSS 0.21%via NVD