Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

October MEDIUM 5.4
CVE-2026-24906

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulner…

Fix: after 4.1.9
Fix from $1,600 2026-04-14
October MEDIUM 5.4
CVE-2026-24907

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulner…

Fix: after 4.1.9
Fix from $1,600 2026-04-14
October MEDIUM 6.8
CVE-2026-22692

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vul…

Fix: 3.7.13 / 4.1.5+
Fix from $1,600 2026-04-14
October MEDIUM 5.4
CVE-2024-25837

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or…

Fix: after 1.3.8
Fix from $1,600 2024-08-16
October MEDIUM 5.4
CVE-2024-25637

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler nam…

Fix: 3.5.15+
Fix from $1,600 2024-06-26
October HIGH 7.8
CVE-2023-25365

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

No fix yet
Fix from $1,950 2024-02-08
October CRITICAL 9.1
CVE-2023-44382

October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms…

Fix: 3.4.15+
Fix from $2,300 2023-12-01
October MEDIUM 5.4
CVE-2023-44383

October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that store…

Fix: 3.5.2+
Fix from $1,600 2023-11-29
October MEDIUM 5.4
CVE-2023-43876

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payl…

No fix yet
Fix from $1,600 2023-09-28
October MEDIUM 5.4
CVE-2023-37692

An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $1,600 2023-07-26
October HIGH 7.2
CVE-2022-35944

October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations t…

Fix: 2.2.34 / 3.0.66+
Fix from $1,950 2022-10-13
October HIGH 8.1
CVE-2022-24800

October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12…

Fix: 1.0.476 / 1.1.12+
Fix from $1,950 2022-07-12
October MEDIUM 5.3
CVE-2022-23655

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatur…

Fix: 1.0.475 / 1.1.11+
Fix from $1,600 2022-02-24
October HIGH 7.2
CVE-2022-21705EPSS 9%

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before render…

Fix: 1.0.474 / 1.1.10+
Fix from $1,950 2022-02-23
October HIGH 8.8
CVE-2021-32649

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…

Fix: 1.0.473 / 1.1.6+
Fix from $1,950 2022-01-14
October HIGH 8.8
CVE-2021-32650

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…

Patch available
Fix from $1,950 2022-01-14
October HIGH 7.2
CVE-2021-41126

October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts whi…

Fix: 2.1.12+
Fix from $1,950 2021-10-06
October CRITICAL 9.1
CVE-2021-32648 KEVEPSS 90%

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an accoun…

Fix: 1.1.5+
Fix from $2,300 2021-08-26
October HIGH 7.4
CVE-2021-29487

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vuln…

Fix: 1.0.472 / 1.1.5+
Fix from $1,950 2021-08-26
October MEDIUM 5.2
CVE-2021-21264

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1…

Fix: after 1.1.1
Fix from $1,600 2021-05-03
October HIGH 7.5
CVE-2021-21265

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly …

Fix: 1.1.2+
Fix from $1,950 2021-03-10
October CRITICAL 9.8
CVE-2021-3311

An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occur…

Fix: after 1.0.471
Fix from $2,300 2021-02-05
October MEDIUM 6.7
CVE-2020-26231

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 (fixed in 1.0.469 and 1.1.0) …

Patch available
Fix from $1,600 2020-11-23
October HIGH 7.5
CVE-2020-15246

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1…

Fix: 1.0.469+
Fix from $1,950 2020-11-23
October MEDIUM 5.4
CVE-2020-15249

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1…

Fix: 1.0.469+
Fix from $1,600 2020-11-23
October MEDIUM 5.2
CVE-2020-15247

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1…

Fix: 1.0.469+
Fix from $1,600 2020-11-23
October MEDIUM 6.3
CVE-2020-15128

In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain …

Fix: 1.0.468+
Fix from $1,600 2020-07-31
October MEDIUM 5.4
CVE-2020-4061

In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in…

Fix: 1.0.467+
Fix from $1,600 2020-07-02
Debugbar CRITICAL 9.8
CVE-2020-11094

The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each reques…

Fix: 3.1.0+
Fix from $2,300 2020-06-04
October MEDIUM 5.1
CVE-2020-5299

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could e…

Fix: 1.0.466+
Fix from $1,600 2020-06-03