VendorsOctoberCMSoctoberall versions
Vulnerabilities

OctoberCMS October

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2026-24907
October CMS has Stored XSS via Event Log Mail Preview
Published 2026-04-14 · Analyzed
5.4EPSS 0.002
CVE-2022-23655
Missing server signature validation in OctoberCMS
Published 2022-02-23 · Modified
5.3EPSS 0.006
CVE-2020-15247
Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.
Published 2020-11-23 · Modified
5.2EPSS 0.003
CVE-2021-21264
Bypass of fix for CVE-2020-26231, Twig sandbox escape
Published 2021-05-03 · Modified
5.2EPSS 0.003
CVE-2020-5299
Potential CSV Injection vector in OctoberCMS
Published 2020-06-03 · Modified
5.1EPSS 0.010
CVE-2020-5295
Local File read vulnerability in OctoberCMS
Published 2020-06-03 · Modified
4.91 PoCEPSS 0.074
CVE-2023-44381
October CMS safe mode bypass using Page template injection
Published 2023-12-01 · Modified
4.9EPSS 0.005
CVE-2024-51991
October CMS Allows Unprotected SVG Rename in Media Manager
Published 2025-05-05 · Analyzed
4.9EPSS 0.004
CVE-2026-25125
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
Published 2026-04-14 · Analyzed
4.9EPSS 0.003
CVE-2020-11083
Stored XSS in October
Published 2020-07-14 · Modified
4.8EPSS 0.011
CVE-2020-5298
Reflected XSS when importing CSV in OctoberCMS
Published 2020-06-03 · Modified
4.8EPSS 0.009
CVE-2024-24764
October Open Redirect for Administrator Accounts
Published 2024-06-26 · Modified
4.8EPSS 0.003
CVE-2026-25133
October CMS has Stored XSS via SVG Filter Bypass
Published 2026-04-14 · Analyzed
4.8EPSS 0.002
CVE-2024-45962
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
Published 2024-10-02 · Analyzed
4.7EPSS 0.005
CVE-2020-15248
Privilege escalation by backend users assigned to the default "Publisher" system role
Published 2020-11-23 · Modified
4.6EPSS 0.003
CVE-2015-5612
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.
Published 2015-09-04 · Modified
4.3EPSS 0.018
CVE-2020-5297
Upload whitelisted files to any directory in OctoberCMS
Published 2020-06-03 · Modified
4.0EPSS 0.012
← Prev2 / 2