Low severity3.1NVD Advisory· Published Sep 8, 2026· Updated Sep 8, 2026
CVE-2026-48707
CVE-2026-48707
Description
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (system/core/uploader.php at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.18.2
- Range: <2.18.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.