Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

October HIGH 8.1
CVE-2018-1999009

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents fun…

Mitigation only
Fix from $1,950 2018-07-23
October MEDIUM 5.4
CVE-2018-1999008

October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that c…

Fix: 1.0.437+
Fix from $1,600 2018-07-23
October MEDIUM 6.1
CVE-2018-7198

October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.

Fix: after 1.0.431
Fix from $1,600 2018-02-18
October HIGH 8.8
CVE-2017-16941

October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by dow…

Fix: after 1.0.428
Fix from $1,950 2017-11-25
October CRITICAL 9.8
CVE-2017-1000194

October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly othe…

Fix: after 1.0.412
Fix from $2,300 2017-11-17
October CRITICAL 9.8
CVE-2017-1000196

October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applicat…

Fix: after 1.0.412
Fix from $2,300 2017-11-17
October CRITICAL 9.8
CVE-2017-1000197

October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the serve…

Fix: after 1.0.412
Fix from $2,300 2017-11-17
October HIGH 7.5
CVE-2017-1000195

October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissi…

Fix: after 1.0.412
Fix from $1,950 2017-11-17
October MEDIUM 6.1
CVE-2017-1000193

October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.

Fix: after 1.0.412
Fix from $1,600 2017-11-17
October HIGH 8.8
CVE-2017-16244

Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an …

Patch available
Fix from $1,950 2017-11-01
October MEDIUM 5.4
CVE-2017-15284

Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code a…

Patch available
Fix from $1,600 2017-10-12
October HIGH 7.2
CVE-2017-1000119EPSS 61%

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applicatio…

No fix yet
Fix from $1,950 2017-10-05
October MEDIUM 5.4
CVE-2015-5613

Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vect…

Patch available
Fix from $1,600 2017-09-28