Octobercms

October

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 21.04.2026 16:19:52
  • Zuletzt bearbeitet 21.04.2026 17:16:36

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend...

  • EPSS -
  • Veröffentlicht 21.04.2026 16:17:06
  • Zuletzt bearbeitet 21.04.2026 17:16:35

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output ...

  • EPSS -
  • Veröffentlicht 21.04.2026 16:16:06
  • Zuletzt bearbeitet 21.04.2026 17:16:30

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Dev...

  • EPSS -
  • Veröffentlicht 21.04.2026 16:16:03
  • Zuletzt bearbeitet 21.04.2026 17:16:24

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft ...

  • EPSS 0.01%
  • Veröffentlicht 14.04.2026 20:47:49
  • Zuletzt bearbeitet 17.04.2026 15:38:09

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such...

  • EPSS 0.01%
  • Veröffentlicht 14.04.2026 20:39:59
  • Zuletzt bearbeitet 17.04.2026 15:38:09

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax fo...

  • EPSS 0.07%
  • Veröffentlicht 14.04.2026 18:16:45
  • Zuletzt bearbeitet 21.04.2026 17:24:26

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. When viewing logged mail messages, HTML content was re...

  • EPSS 0.07%
  • Veröffentlicht 14.04.2026 18:16:45
  • Zuletzt bearbeitet 21.04.2026 17:24:04

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields (used for paragraph styles, inline ...

  • EPSS 0.01%
  • Veröffentlicht 14.04.2026 16:48:04
  • Zuletzt bearbeitet 21.04.2026 17:23:38

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() h...

  • EPSS 0.05%
  • Veröffentlicht 10.01.2026 03:14:11
  • Zuletzt bearbeitet 20.01.2026 16:06:07

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permissio...