Reflected Cross-Site Scripting Vulnerability in October CMS by October
CVE-2026-27937
3.1LOW
What is CVE-2026-27937?
Prior to versions 3.7.16 and 4.1.16, October CMS contained a reflected Cross-Site Scripting vulnerability within the backend DataTable widget. This issue arose when a query parameter was rendered without adequate output escaping, allowing malicious actors to inject arbitrary scripts into web pages viewed by users. The vulnerability has since been addressed in the updated versions.
Affected Version(s)
october >= 4.0.0, < 4.1.16 < 4.0.0, 4.1.16
october < 3.7.16 < 3.7.16
