Vulnerabilities (CVE)

Filtered by vendor Instantcms Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14382 1 Instantcms 1 Instantcms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
InstantCMS 2.10.1 has /redirect?url= XSS.
CVE-2013-10051 1 Instantcms 1 Instantcms 2026-06-16 N/A 9.8 CRITICAL
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote attacker can exploit this flaw by sending a crafted HTTP GET request with a base64-encoded payload in the Cmd header, resulting in arbitrary PHP code execution within the context of the web server.