CVE-2026-28281
HIGHInstantCMS <2.18.1 - CSRF
Title source: llmDescription
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability is fixed in 2.18.1.
Scores
CVSS v3
7.1
EPSS
0.0001
EPSS Percentile
2.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Classification
CWE
CWE-352
Status
draft
Timeline
Published
Mar 10, 2026
Tracked Since
Mar 11, 2026