VendorsOctoberCMSoctoberany version
Vulnerabilities

OctoberCMS October any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2026-25125
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
Published 2026-04-14 · Analyzed
4.9EPSS 0.003
CVE-2020-11083
Stored XSS in October
Published 2020-07-14 · Modified
4.8EPSS 0.011
CVE-2020-5298
Reflected XSS when importing CSV in OctoberCMS
Published 2020-06-03 · Modified
4.8EPSS 0.009
CVE-2024-24764
October Open Redirect for Administrator Accounts
Published 2024-06-26 · Modified
4.8EPSS 0.003
CVE-2026-25133
October CMS has Stored XSS via SVG Filter Bypass
Published 2026-04-14 · Analyzed
4.8EPSS 0.002
CVE-2020-15248
Privilege escalation by backend users assigned to the default "Publisher" system role
Published 2020-11-23 · Modified
4.6EPSS 0.003
CVE-2015-5612
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.
Published 2015-09-04 · Modified
4.3EPSS 0.018
CVE-2020-5297
Upload whitelisted files to any directory in OctoberCMS
Published 2020-06-03 · Modified
4.0EPSS 0.012
← Prev2 / 2