Vulnerability Details CVE-2026-28507
Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.4%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-28507
-
cpe:2.3:a:withknown:known:0.6
-
cpe:2.3:a:withknown:known:0.6.5
-
cpe:2.3:a:withknown:known:0.7
-
cpe:2.3:a:withknown:known:0.7.1
-
cpe:2.3:a:withknown:known:0.7.5
-
cpe:2.3:a:withknown:known:0.7.6
-
cpe:2.3:a:withknown:known:0.7.7
-
cpe:2.3:a:withknown:known:0.7.7.1
-
cpe:2.3:a:withknown:known:0.7.8
-
cpe:2.3:a:withknown:known:0.7.8.5
-
cpe:2.3:a:withknown:known:0.8
-
cpe:2.3:a:withknown:known:0.8.1
-
cpe:2.3:a:withknown:known:0.8.2
-
cpe:2.3:a:withknown:known:0.8.3
-
cpe:2.3:a:withknown:known:0.8.3.1
-
cpe:2.3:a:withknown:known:0.8.4
-
cpe:2.3:a:withknown:known:0.8.5
-
cpe:2.3:a:withknown:known:0.9
-
cpe:2.3:a:withknown:known:0.9.0.1
-
cpe:2.3:a:withknown:known:0.9.0.2
-
cpe:2.3:a:withknown:known:0.9.0.3
-
cpe:2.3:a:withknown:known:0.9.0.4
-
cpe:2.3:a:withknown:known:0.9.1
-
cpe:2.3:a:withknown:known:0.9.2
-
cpe:2.3:a:withknown:known:0.9.9
-
cpe:2.3:a:withknown:known:1.0.0
-
cpe:2.3:a:withknown:known:1.2.2
-
cpe:2.3:a:withknown:known:1.3.1