Stored Cross-Site Scripting Vulnerability in October CMS Backend Editor Settings
CVE-2026-24906

5.1MEDIUM

Key Information:

Vendor

Octobercms

Status
Vendor
CVE Published:
14 April 2026

What is CVE-2026-24906?

October CMS has a Stored Cross-Site Scripting vulnerability that affects versions prior to 3.7.14 and 4.1.10. The vulnerability resides in the Backend Editor Settings, where the Markup Classes fields fail to properly sanitize input for valid CSS class name characters. This can lead to malicious values being rendered unsanitized in Froala editor dropdown menus, enabling JavaScript execution when a user interacts with the RichEditor. The risk is particularly pronounced if a superuser opens the RichEditor during routine content editing, potentially leading to privilege escalation. Mitigation measures include restricting editor settings permissions to only fully trusted administrators. The vulnerability has been remediated in the specified versions.

Affected Version(s)

october < 3.7.14 < 3.7.14

october >= 4.0.0, < 4.1.10 < 4.0.0, 4.1.10

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.