CVE Explorer
CVE-2026-28281
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability is fixed in 2.18.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"icms2","vendor":"instantsoft","versions":[{"status":"affected","version":"< 2.18.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8dd08ad3ec2e8fc9024d06b6b80936ab9d29d8c077ae960b53812976bfb79f8f · sha256:cd8fefeed0a5f869… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8dd08ad3ec2e8fc9024d06b6b80936ab9d29d8c077ae960b53812976bfb79f8f · sha256:cd8fefeed0a5f869… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352: Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dd08ad3ec2e8fc9024d06b6b80936ab9d29d8c077ae960b53812976bfb79f8f · sha256:cd8fefeed0a5f869… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/instantsoft/icms2/security/advisories/GHSA-pp43-262q-h73m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/instantsoft/icms2/security/advisories/GHSA-pp43-262q-h73m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dd08ad3ec2e8fc9024d06b6b80936ab9d29d8c077ae960b53812976bfb79f8f · sha256:cd8fefeed0a5f869… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.