Description
A vulnerability has been found in InstantSoft icms2 up to 2.18.2. This issue affects the function index of the file templates/default/controllers/messages/index.tpl.php of the component Private Message Handler. Such manipulation of the argument nickname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 3a1ec8fcb073a46d06a2ab83bc2bf68225834281. It is best practice to apply a patch to resolve this issue.
Published: 2026-10-11
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting via the nickname field in the Private Message index controller
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Private Message Handler’s index.tpl.php file, where a manipulation of the nickname argument leads to script code being injected into the page. The flaw allows an attacker to embed malicious JavaScript in page responses, which is executed in the victim’s browser. This can be used to steal session data, deface the site or facilitate further attacks. The weakness is classified as input validation and code injection: CWE‑79 and CWE‑94.

Affected Systems

InstantSoft’s icms2 content management system versions up to and including 2.18.2 are affected. The vulnerability impacts the public index feature handling private messages and requires the system to be online in order for the flaw to be exploitable.

Risk and Exploitability

The flaw is rated CVSS 5.1, indicating a moderate severity. The EPSS score is not available and the vulnerability is not listed in the National Cybersecurity Center’s KEV catalog. The description confirms that the attack can be launched remotely and that the exploit has been publicly disclosed, implying a real‑world risk if patches are not applied.

Generated by OpenCVE AI on October 11, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch identified by commit 3a1ec8fcb073a46d06a2ab83bc2bf68225834281 to fix the nickname handling in the index controller.
  • Validate and sanitize the nickname input on the server side, ensuring no script tags or executable code are stored or rendered.
  • Implement a strict Content Security Policy or a web application firewall to block execution of injected scripts and reduce the impact of any remaining XSS vectors.

Generated by OpenCVE AI on October 11, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in InstantSoft icms2 up to 2.18.2. This issue affects the function index of the file templates/default/controllers/messages/index.tpl.php of the component Private Message Handler. Such manipulation of the argument nickname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 3a1ec8fcb073a46d06a2ab83bc2bf68225834281. It is best practice to apply a patch to resolve this issue.
Title InstantSoft icms2 Private Message index.tpl.php index cross site scripting
First Time appeared Instantsoft
Instantsoft icms2
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:instantsoft:icms2:*:*:*:*:*:*:*:*
Vendors & Products Instantsoft
Instantsoft icms2
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Instantsoft Icms2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T09:15:16.508Z

Reserved: 2026-10-10T15:04:16.038Z

Link: CVE-2026-108566

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T10:16:38.727

Modified: 2026-10-11T10:16:38.727

Link: CVE-2026-108566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T10:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')