CVE-2026-54611

Source
https://cve.org/CVERecord?id=CVE-2026-54611
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54611.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54611
Aliases
  • GHSA-vvgv-h28h-p2m5
Published
2026-09-08T17:16:08Z
Modified
2026-09-10T03:47:32Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
InstantCMS has Remote Code Execution in package installer
Details

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-434",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54611.json"
}
References

Affected packages

Git / github.com/instantsoft/icms2

Affected ranges

Type
GIT
Repo
https://github.com/instantsoft/icms2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.18.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.13.0
2.13.1
2.14.0
2.14.1
2.14.2
2.14.3
2.15.0
2.15.1
2.15.2
2.16.0
2.16.1
2.16.2
2.17.0
2.17.1
2.17.2
2.17.3
2.18.0
2.18.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.2
2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54611.json"