VendorsOctoberCMSoctoberany version
Vulnerabilities

OctoberCMS October any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2021-3311
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.
Published 2021-02-05 · Modified
9.8EPSS 0.029
CVE-2017-1000196
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.
Published 2017-11-17 · Modified
9.8EPSS 0.019
CVE-2017-1000194
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.
Published 2017-11-17 · Modified
9.8EPSS 0.012
CVE-2017-1000197
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.
Published 2017-11-17 · Modified
9.8EPSS 0.012
CVE-2021-32648
Account Takeover in Octobercms
Published 2021-08-26 · Analyzed
9.1KEVEPSS 0.904
CVE-2023-44382
October CMS safe mode bypass using Twig sandbox escape
Published 2023-12-01 · Modified
9.1EPSS 0.009
CVE-2017-16941
October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a theme ZIP archive from /backend/cms/themes, and then uploading and importing a modified archive with two new files: a .php file and a .htaccess file. NOTE: the vendor says "I don't think [an attacker able to login to the system under an account that has access to manage/upload themes] is a threat model that we need to be considering.
Published 2017-11-25 · Modified
8.8EPSS 0.016
CVE-2021-32649
Authenticated file write leads to remote code execution in october/system
Published 2022-01-14 · Modified
8.8EPSS 0.013
CVE-2022-21705
Authenticated remote code execution in octobercms
Published 2022-02-23 · Modified
8.5EPSS 0.087
CVE-2018-1999009
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.
Published 2018-07-23 · Modified
8.1EPSS 0.024
CVE-2022-24800
Race Condition in October CMS upload process
Published 2022-07-12 · Modified
8.1EPSS 0.014
CVE-2021-21265
October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers
Published 2021-03-10 · Modified
7.5EPSS 0.017
CVE-2020-15246
Local File Inclusion by unauthenticated users
Published 2020-11-23 · Modified
7.5EPSS 0.017
CVE-2017-1000195
October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.
Published 2017-11-17 · Modified
7.5EPSS 0.015
CVE-2021-29487
Authentication bypass in Octobercms
Published 2021-08-26 · Modified
7.4EPSS 0.009
CVE-2021-41126
Deleted Admin Can Sign In to Admin Interface
Published 2021-10-06 · Modified
7.2EPSS 0.011
CVE-2022-35944
October CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)
Published 2022-10-13 · Modified
7.2EPSS 0.009
CVE-2026-22692
October CMS: Twig Sandbox Bypass via Collection Methods
Published 2026-04-14 · Analyzed
6.8EPSS 0.004
CVE-2020-15128
Reliance on Cookies without validation in OctoberCMS
Published 2020-07-31 · Modified
6.3EPSS 0.007
CVE-2020-5296
Arbitrary File Deletion vulnerability in OctoberCMS
Published 2020-06-03 · Modified
6.2EPSS 0.014
CVE-2018-7198
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
Published 2018-02-18 · Modified
6.11 PoCEPSS 0.023
CVE-2017-1000193
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
Published 2017-11-17 · Modified
6.1EPSS 0.010
CVE-2025-61674
October CMS Vulnerable to Stored XSS via Editor and Branding Styles
Published 2026-01-10 · Analyzed
6.1EPSS 0.003
CVE-2025-61676
October CMS Vulnerable to Stored XSS via Branding Styles
Published 2026-01-10 · Analyzed
6.1EPSS 0.003
CVE-2015-5613
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving a file title, a different vulnerability than CVE-2015-5612.
Published 2017-09-27 · Modified
5.4EPSS 0.009
CVE-2020-4061
Cross-site Scripting in OctoberPotential self-XSS when pasting content from malicious websites
Published 2020-07-02 · Modified
5.4EPSS 0.008
CVE-2018-1999008
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with XSS content. This attack appear to be exploitable via an Authenticated user with media module permission who can create arbitrary folder name (XSS). This vulnerability appears to have been fixed in build 437.
Published 2018-07-23 · Modified
5.4EPSS 0.005
CVE-2020-15249
Stored XSS by authenticated backend user with access to upload files
Published 2020-11-23 · Modified
5.4EPSS 0.005
CVE-2023-44383
October CMS stored XSS by authenticated backend user with improper configuration
Published 2023-11-29 · Modified
5.4EPSS 0.004
CVE-2024-25637
Reflected XSS via X-October-Request-Handler Header
Published 2024-06-26 · Analyzed
5.4EPSS 0.003
CVE-2026-24906
October CMS has Stored XSS in its Backend Editor Markup Classes
Published 2026-04-14 · Analyzed
5.4EPSS 0.003
CVE-2024-25837
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.
Published 2024-08-16 · Analyzed
5.4EPSS 0.002
CVE-2026-24907
October CMS has Stored XSS via Event Log Mail Preview
Published 2026-04-14 · Analyzed
5.4EPSS 0.002
CVE-2022-23655
Missing server signature validation in OctoberCMS
Published 2022-02-23 · Modified
5.3EPSS 0.006
CVE-2020-15247
Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.
Published 2020-11-23 · Modified
5.2EPSS 0.003
CVE-2021-21264
Bypass of fix for CVE-2020-26231, Twig sandbox escape
Published 2021-05-03 · Modified
5.2EPSS 0.003
CVE-2020-5299
Potential CSV Injection vector in OctoberCMS
Published 2020-06-03 · Modified
5.1EPSS 0.010
CVE-2020-5295
Local File read vulnerability in OctoberCMS
Published 2020-06-03 · Modified
4.91 PoCEPSS 0.074
CVE-2023-44381
October CMS safe mode bypass using Page template injection
Published 2023-12-01 · Modified
4.9EPSS 0.005
CVE-2024-51991
October CMS Allows Unprotected SVG Rename in Media Manager
Published 2025-05-05 · Analyzed
4.9EPSS 0.004
1 / 2Next →