Reflected Cross-Site Scripting Vulnerability in October CMS by October
CVE-2026-27937

3.1LOW

Key Information:

Vendor

Octobercms

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-27937?

Prior to versions 3.7.16 and 4.1.16, October CMS contained a reflected Cross-Site Scripting vulnerability within the backend DataTable widget. This issue arose when a query parameter was rendered without adequate output escaping, allowing malicious actors to inject arbitrary scripts into web pages viewed by users. The vulnerability has since been addressed in the updated versions.

Affected Version(s)

october >= 4.0.0, < 4.1.16 < 4.0.0, 4.1.16

october < 3.7.16 < 3.7.16

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.