THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-48707 (LOW 3.1) — InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redi

[NVD] CVE-2026-48707 (LOW 3.1) — InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redi

mednvdPublished 2026-09-08

CVE-2026-48707 CVSS: 3.1 LOW Published: 2026-09-08T18:17:38.167

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48707