PT-2026-24135 · Unknown · Instantcms
0Xhamy
·
Published
2026-03-09
·
Updated
2026-03-13
·
CVE-2026-28281
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
InstantCMS versions prior to 2.18.1
Description
InstantCMS does not properly validate Cross-Site Request Forgery (CSRF) tokens. This allows attackers to perform actions on behalf of a user without their knowledge. Specifically, an attacker could grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests.
Recommendations
Update to InstantCMS version 2.18.1 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Instantcms