Stored Cross-Site Scripting Vulnerability in October CMS Backend Editor Settings
CVE-2026-24906
What is CVE-2026-24906?
October CMS has a Stored Cross-Site Scripting vulnerability that affects versions prior to 3.7.14 and 4.1.10. The vulnerability resides in the Backend Editor Settings, where the Markup Classes fields fail to properly sanitize input for valid CSS class name characters. This can lead to malicious values being rendered unsanitized in Froala editor dropdown menus, enabling JavaScript execution when a user interacts with the RichEditor. The risk is particularly pronounced if a superuser opens the RichEditor during routine content editing, potentially leading to privilege escalation. Mitigation measures include restricting editor settings permissions to only fully trusted administrators. The vulnerability has been remediated in the specified versions.
Affected Version(s)
october < 3.7.14 < 3.7.14
october >= 4.0.0, < 4.1.10 < 4.0.0, 4.1.10
