CVE-2025-61674
- EPSS 0.04%
- Veröffentlicht 10.01.2026 03:14:11
- Zuletzt bearbeitet 20.01.2026 16:06:07
October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permissio...
CVE-2025-61676
- EPSS 0.04%
- Veröffentlicht 10.01.2026 03:14:00
- Zuletzt bearbeitet 20.01.2026 16:05:36
October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permi...
CVE-2024-51991
- EPSS 0.31%
- Veröffentlicht 05.05.2025 17:04:53
- Zuletzt bearbeitet 03.09.2025 18:54:25
October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG ...
CVE-2024-45962
- EPSS 0.27%
- Veröffentlicht 02.10.2024 20:15:11
- Zuletzt bearbeitet 29.09.2025 17:30:04
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary c...
CVE-2024-25837
- EPSS 0.16%
- Veröffentlicht 16.08.2024 18:15:08
- Zuletzt bearbeitet 28.04.2025 14:06:50
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.
CVE-2024-25637
- EPSS 0.82%
- Veröffentlicht 26.06.2024 16:15:10
- Zuletzt bearbeitet 29.09.2025 14:09:16
October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot ...
CVE-2024-24764
- EPSS 0.1%
- Veröffentlicht 26.06.2024 01:15:47
- Zuletzt bearbeitet 21.11.2024 08:59:39
October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october:/...
CVE-2023-25365
- EPSS 0.05%
- Veröffentlicht 08.02.2024 22:15:08
- Zuletzt bearbeitet 17.06.2025 15:15:35
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3
CVE-2023-44382
- EPSS 0.25%
- Veröffentlicht 01.12.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:25:47
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitt...
CVE-2023-44381
- EPSS 0.18%
- Veröffentlicht 01.12.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:25:46
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitt...