CVE-2020-26641: Idreamsoft Icms

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.

Affected products

Published 2021-05-28. Last modified 2026-06-17.