PT-2026-24135 · Unknown · Instantcms

0Xhamy

·

Published

2026-03-09

·

Updated

2026-03-13

·

CVE-2026-28281

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions InstantCMS versions prior to 2.18.1
Description InstantCMS does not properly validate Cross-Site Request Forgery (CSRF) tokens. This allows attackers to perform actions on behalf of a user without their knowledge. Specifically, an attacker could grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests.
Recommendations Update to InstantCMS version 2.18.1 or later.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-28281
GHSA-PP43-262Q-H73M

Affected Products

Instantcms