Octobercms

October

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.93%
  • Veröffentlicht 29.11.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:25:47

October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 28.09.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 08:24:56

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 26.07.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:12:07

An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.

  • EPSS 0.5%
  • Veröffentlicht 13.10.2022 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:12:01

October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel....

  • EPSS 2.93%
  • Veröffentlicht 12.07.2022 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:07

October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` meth...

  • EPSS 0.14%
  • Veröffentlicht 24.02.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:01

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private keys. Users ...

  • EPSS 81.51%
  • Veröffentlicht 23.02.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:16

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploi...

Exploit
  • EPSS 1.09%
  • Veröffentlicht 14.01.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:27

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using the theme import feature. This ...

  • EPSS 0.5%
  • Veröffentlicht 14.01.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:27

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP...

  • EPSS 0.49%
  • Veröffentlicht 06.10.2021 18:15:11
  • Zuletzt bearbeitet 21.11.2024 06:25:31

October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the backend using October CMS v2.0. Th...