THREAT OPS › Threat News › [NVD] CVE-2026-48707 (LOW 3.1) — InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redi
[NVD] CVE-2026-48707 (LOW 3.1) — InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redi
CVE-2026-48707 CVSS: 3.1 LOW Published: 2026-09-08T18:17:38.167
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP
Indicators of compromise
- CVE-2026-48707cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48707