CVE-2024-50348 | InstantCMS has a Cross Site Scripting Vulnerability
Exp
InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the XSS (Cross Site Scripting) payload and execute. This vulnerability is fixed in 2.16.3.
Conclusion & alert: CVE-2024-50348 is rated High Exploit Risk (60.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.59%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2024-50348
Exploit prediction scoring system (EPSS) score for CVE-2024-50348
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).