Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-24906 October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulner… October after 4.1.9 Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-24907 October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulner… October after 4.1.9 Fix from $1,6002026-04-14 MEDIUM 6.8 CVE-2026-22692 October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vul… October 3.7.13 / 4.1.5+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2024-25837 A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or… October after 1.3.8 Fix from $1,6002024-08-16 MEDIUM 5.4 CVE-2024-25637 October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler nam… October 3.5.15+ Fix from $1,6002024-06-26 HIGH 7.8 CVE-2023-25365 Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3 October No fix yet Fix from $1,9502024-02-08 CRITICAL 9.1 CVE-2023-44382 October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms… October 3.4.15+ Fix from $2,3002023-12-01 MEDIUM 5.4 CVE-2023-44383 October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that store… October 3.5.2+ Fix from $1,6002023-11-29 MEDIUM 5.4 CVE-2023-43876 A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payl… October No fix yet Fix from $1,6002023-09-28 MEDIUM 5.4 CVE-2023-37692 An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file. October No fix yet Fix from $1,6002023-07-26 HIGH 7.2 CVE-2022-35944 October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations t… October 2.2.34 / 3.0.66+ Fix from $1,9502022-10-13 HIGH 8.1 CVE-2022-24800 October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12… October 1.0.476 / 1.1.12+ Fix from $1,9502022-07-12 MEDIUM 5.3 CVE-2022-23655 Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatur… October 1.0.475 / 1.1.11+ Fix from $1,6002022-02-24 HIGH 7.2 CVE-2022-21705EPSS 9% Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before render… October 1.0.474 / 1.1.10+ Fix from $1,9502022-02-23 HIGH 8.8 CVE-2021-32649 October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att… October 1.0.473 / 1.1.6+ Fix from $1,9502022-01-14 HIGH 8.8 CVE-2021-32650 October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att… October Patch available Fix from $1,9502022-01-14 HIGH 7.2 CVE-2021-41126 October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts whi… October 2.1.12+ Fix from $1,9502021-10-06 CRITICAL 9.1 CVE-2021-32648 KEVEPSS 90% octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an accoun… October 1.1.5+ Fix from $2,3002021-08-26 HIGH 7.4 CVE-2021-29487 octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vuln… October 1.0.472 / 1.1.5+ Fix from $1,9502021-08-26 MEDIUM 5.2 CVE-2021-21264 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1… October after 1.1.1 Fix from $1,6002021-05-03 HIGH 7.5 CVE-2021-21265 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly … October 1.1.2+ Fix from $1,9502021-03-10 CRITICAL 9.8 CVE-2021-3311 An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occur… October after 1.0.471 Fix from $2,3002021-02-05 MEDIUM 6.7 CVE-2020-26231 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 (fixed in 1.0.469 and 1.1.0) … October Patch available Fix from $1,6002020-11-23 HIGH 7.5 CVE-2020-15246 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1… October 1.0.469+ Fix from $1,9502020-11-23 MEDIUM 5.4 CVE-2020-15249 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1… October 1.0.469+ Fix from $1,6002020-11-23 MEDIUM 5.2 CVE-2020-15247 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1… October 1.0.469+ Fix from $1,6002020-11-23 MEDIUM 6.3 CVE-2020-15128 In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain … October 1.0.468+ Fix from $1,6002020-07-31 MEDIUM 5.4 CVE-2020-4061 In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in… October 1.0.467+ Fix from $1,6002020-07-02 CRITICAL 9.8 CVE-2020-11094 The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each reques… Debugbar 3.1.0+ Fix from $2,3002020-06-04 MEDIUM 5.1 CVE-2020-5299 In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could e… October 1.0.466+ Fix from $1,6002020-06-03