📦 October

by Octobercms

🔍 What is October?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-44382

CRITICAL CVSS 9.1 Dec 1, 2023

October CMS has a critical vulnerability where authenticated backend users with specific editor permissions can bypass the Twig sandbox and execute arbitrary PHP code even when safe_mode is enabled. T...

CVE-2021-3311

CRITICAL CVSS 9.8 Feb 5, 2021

CVE-2021-3311 is an authentication bypass vulnerability in October CMS where old session IDs become reactivated after a new login occurs. This allows attackers with knowledge of previously invalidated...

CVE-2023-25365

HIGH CVSS 7.8 Feb 8, 2024

This vulnerability allows a local attacker to upload malicious .mp3 files containing XSS payloads to October CMS, which can then execute arbitrary JavaScript in victims' browsers when accessed. It aff...

CVE-2022-21705

HIGH CVSS 7.2 Feb 23, 2022

This CVE allows authenticated users with page management permissions in OctoberCMS to bypass safe mode restrictions and execute arbitrary code through improper input sanitization. It affects admin pan...

CVE-2021-32649

HIGH CVSS 8.8 Jan 14, 2022

October CMS versions before 1.0.473 and 1.1.6 contain a vulnerability where authenticated backend users with 'create, modify and delete website pages' privileges can execute arbitrary PHP code by inje...

CVE-2021-41126

HIGH CVSS 7.2 Oct 6, 2021

This vulnerability allows deleted administrator accounts to still authenticate and access the October CMS backend. It affects October CMS v2.0 installations where administrator accounts have been dele...

CVE-2021-29487

HIGH CVSS 7.4 Aug 26, 2021

CVE-2021-29487 is an authentication bypass vulnerability in October CMS that allows unauthenticated attackers to take over user accounts. Attackers need the Laravel secret key to exploit this vulnerab...

CVE-2024-51991

MEDIUM CVSS 4.9 May 5, 2025

This vulnerability allows authenticated administrators in October CMS to bypass SVG file sanitization by uploading files with permitted extensions (like .jpg) and later renaming them to .svg. It affec...

CVE-2024-25837

MEDIUM CVSS 5.4 Aug 16, 2024

This stored XSS vulnerability in October CMS Bloghub Plugin allows attackers to inject malicious scripts into blog comments, which then execute in visitors' browsers. Attackers can steal session cooki...