CVE-2026-54611
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
- EPSS probability
- 0.52%
- CWE
- CWE-94, CWE-434
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- instantsoft icms2
Weakness type
Related vulnerabilities
- CVE-2026-87817 — GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2026-86076 — n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
- CVE-2026-86083 — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
- CVE-2026-85983 — Local Privilege Escalation in Auth0 AD/LDAP Connector
- CVE-2026-78625 — Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration
- CVE-2026-78545 — Improper Input Sanitization in Okta Access Gateway Application Label Configuration