octobercms Latest Vulnerabilities
Latest vulnerabilities published by octobercms
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
PHP Object Injection Vulnerability in October Content Management System
CVE-2026-49400OctobercmsOctober3.3LOWTwig Sandbox Security Bypass in October CMS by October
CVE-2026-46696OctobercmsSystem3.3LOWFile Operations Vulnerability in October CMS by October
CVE-2026-29179OctobercmsOctober3.3LOWReflected Cross-Site Scripting Vulnerability in October CMS by October
CVE-2026-27937OctobercmsOctober3.1LOWDatabase Manipulation Vulnerability in October CMS by October
CVE-2026-26274OctobercmsOctober6.6MEDIUMServer-Side Information Disclosure in October CMS by October
CVE-2026-26067OctobercmsOctober4.9MEDIUMStored Cross-Site Scripting Vulnerability in October CMS by October
CVE-2026-25133OctobercmsOctober4.8MEDIUMServer-Side Information Disclosure in October CMS
CVE-2026-25125OctobercmsOctober4.9MEDIUMStored Cross-Site Scripting Vulnerability in October CMS Event Log Feature
CVE-2026-24907OctobercmsOctober5.1MEDIUMStored Cross-Site Scripting Vulnerability in October CMS Backend Editor Settings
CVE-2026-24906OctobercmsOctober5.1MEDIUMSandbox Bypass Vulnerability in October CMS by October
CVE-2026-22692OctobercmsOctober4.9MEDIUMCross-Site Scripting Vulnerability in October CMS Backend Configuration
CVE-2025-61674OctobercmsOctober6.1MEDIUMCross-Site Scripting Vulnerability in October CMS Backend Configuration
CVE-2025-61676OctobercmsOctober6.1MEDIUMUnauthorized File Upload Vulnerability in October CMS by October
CVE-2024-51991OctobercmsOctober1.1LOWUnescaped HTML Reflected in AJAX Handler Name
CVE-2024-25637OctobercmsOctober3.1LOWOctober CMS safe mode bypass using Page template injection
CVE-2023-44381octobercmsoctober4.9MEDIUMOctober CMS safe mode bypass using Twig sandbox escape
CVE-2023-44382octobercmsoctober9.1CRITICALOctober CMS stored XSS by authenticated backend user with improper configuration
CVE-2023-44383OctobercmsOctober5.4MEDIUMCross-Site Scripting Flaw in October CMS Installation Affects Version 3.4.16
CVE-2023-43876OctobercmsOctoberπΎπ‘5.4MEDIUMArbitrary File Upload Vulnerability in October CMS by October
CVE-2023-37692OctobercmsOctober5.4MEDIUMOctober CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)
CVE-2022-35944OctobercmsOctober6.2MEDIUMFile Path Vulnerability in October CMS by October
CVE-2017-1000197OctobercmsOctober9.8CRITICALCross Site Scripting Vulnerability in October CMS Media Module by October
CVE-2018-1999008OctobercmsOctober5.4MEDIUMLocal File Inclusion Vulnerability in October CMS by October
CVE-2018-1999009OctobercmsOctober8.1HIGHRace Condition in October CMS upload process
CVE-2022-24800OctobercmsOctober8.1HIGH