Browse all 22 CVE security advisories affecting instantsoft. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Instantsoft operates as a provider of enterprise software solutions, primarily focusing on document management and workflow automation systems. Security audits have identified twenty distinct Common Vulnerabilities and Exposures (CVEs) associated with its platform, indicating a history of significant security oversight. The most prevalent vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), which allow attackers to execute arbitrary commands or inject malicious scripts into web pages. Additionally, instances of privilege escalation have been documented, enabling unauthorized users to gain elevated access rights within the system. These flaws often stem from insufficient input validation and improper access control mechanisms. While no single catastrophic data breach has been widely publicized, the cumulative nature of these CVEs suggests systemic weaknesses in the software’s architecture. Organizations relying on Instantsoft must prioritize rigorous patch management and continuous security monitoring to mitigate these known risks effectively.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-48707 | InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning — icms2 CWE-918 | 3.1 | Low | 2026-09-08 |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer — icms2 CWE-94 | 5.5 | Medium | 2026-09-08 |
| CVE-2026-28281 | InstantCMS has Multiple CSRF Vulnerabilities — icms2 CWE-352 | 7.1 | High | 2026-03-09 |
| CVE-2025-59055 | InstantCMS vulnerable to Server-Side Request Forgery via package installer — icms2 CWE-918 | 4.7 | Medium | 2025-09-11 |
| CVE-2024-50348 | InstantCMS has a Cross Site Scripting Vulnerability — icms2 CWE-79 | 5.4 | Medium | 2024-10-29 |
| CVE-2024-31213 | InstantCMS Open Redirect vulnerability — icms2 CWE-601 | 3.5 | Low | 2024-04-05 |
| CVE-2024-31212 | SQL injection in index_chart_data action — icms2 CWE-89 | 6.7 | Medium | 2024-04-04 |
This page lists every published CVE security advisory associated with instantsoft. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.