Known Vulnerabilities for products from Instantcms
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Instantcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-4928 json | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | 7.2 - HIGH | 2023-09-13 | 2023-09-15 |
| CVE-2023-4879 json | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. | 4.8 - MEDIUM | 2023-09-10 | 2023-09-18 |
| CVE-2023-4878 json | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 5.4 - MEDIUM | 2023-09-10 | 2023-09-19 |
| CVE-2023-4704 json | External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 4.9 - MEDIUM | 2023-09-01 | 2023-09-07 |
| CVE-2023-4655 json | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. | 6.1 - MEDIUM | 2023-08-31 | 2023-09-01 |
| CVE-2023-4654 json | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1. | 3.5 - LOW | 2023-08-31 | 2023-09-01 |
| CVE-2023-4653 json | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 4.8 - MEDIUM | 2023-08-31 | 2023-09-01 |
| CVE-2023-4652 json | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 5.4 - MEDIUM | 2023-08-31 | 2023-09-01 |
| CVE-2023-4651 json | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1. | 5.4 - MEDIUM | 2023-08-31 | 2023-09-01 |
| CVE-2023-4650 json | Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 4.7 - MEDIUM | 2023-08-31 | 2023-09-05 |
| CVE-2023-4649 json | Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. | 5.4 - MEDIUM | 2023-08-31 | 2023-09-01 |
| CVE-2023-4381 json | Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 4.3 - MEDIUM | 2023-08-16 | 2023-08-22 |
| CVE-2023-4189 json | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 4.8 - MEDIUM | 2023-08-05 | 2023-08-09 |
| CVE-2023-4188 json | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 9.1 - CRITICAL | 2023-08-05 | 2023-08-09 |
| CVE-2023-4187 json | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | 4.8 - MEDIUM | 2023-08-05 | 2023-08-09 |
| CVE-2018-14382 json | InstantCMS 2.10.1 has /redirect?url= XSS. | 6.1 - MEDIUM | 2018-07-18 | 2018-09-12 |
Known software with vulnerabilities from Instantcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Instantcms | Instantcms | 2.10.1 |