ZeroHour

Vulnerabilities

56 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22692
+4 in the same advisory: …24906 …24907 …25125 …25133
October is a Content Management System (CMS) and web platform.

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections. Exploitation requires authenticated backend access with CMS template editing permissions and only affects installations with CMS_SAFE_MODE enabled (disabled by default). This issue has been fixed in versions 3.7.13 and 4.1.5. To workaround this issue, users can disable CMS_SAFE_MODE if untrusted template editing is not required, and restrict CMS template editing permissions to fully trusted administrators only.

NVD description · AI analysis pending
6.8
group max
<1%
  • octobercms october
CVE-2025-61676
+1 in the same advisory: …61674
October is a Content Management System (CMS) and web platform.

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

NVD description · AI analysis pending
4.8<1%
  • octobercms october
CVE-2024-51991
October is a Content Management System (CMS) and web platform.

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files uploaded using the media manager. This vulnerability allows an authenticated user to bypass this protection by uploading it with a permitted extension (for example, .jpg or .png) and later modifying it to the .svg extension. This vulnerability assumes a trusted user will attack another trusted user and cannot be actively exploited without access to the administration panel and interaction from the other user. This issue has been patched in v3.7.5.

NVD description · AI analysis pending
1.1<1%
  • octobercms october
CVE-2024-45962
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system.

October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.

NVD description · AI analysis pending
4.7<1% PoC
  • octobercms october
CVE-2024-25837
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.

NVD description · AI analysis pending
5.4<1%
  • octobercms october
CVE-2024-25637
+1 in the same advisory: …24764
October is a self-hosted CMS platform based on the Laravel PHP Framework.

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.

NVD description · AI analysis pending
5.4
group max
<1%
  • octobercms october
CVE-2023-25365
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

NVD description · AI analysis pending
7.8<1% PoC
  • octobercms october
CVE-2023-44382
+1 in the same advisory: …44381
October is a Content Management System (CMS) and web platform to assist with development workflow.

October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to `cms.safe_mode` being enabled can write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This issue has been patched in 3.4.15.

NVD description · AI analysis pending
9.1
group max
<1%
  • octobercms october
CVE-2023-44383
October is a Content Management System (CMS) and web platform to assist with development workflow.

October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2.

NVD description · AI analysis pending
5.4<1%
  • octobercms october
CVE-2023-43876
A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injecte

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

NVD description · AI analysis pending
5.4<1% PoC
  • octobercms october
CVE-2023-37692
An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.

An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.

NVD description · AI analysis pending
5.4<1% PoC
  • octobercms october
CVE-2022-35944
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework.

October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has access to the admin panel and permission to open the "Editor" section, they can bypass the Safe Mode (`cms.safe_mode`) restriction to introduce new PHP code in a CMS template using a specially crafted request. The issue has been patched in versions 2.2.34 and 3.0.66.

NVD description · AI analysis pending
7.2<1%
  • octobercms october
CVE-2022-24800
October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework.

October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` method, an unauthenticated user can perform remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects plugins that expose the `October\Rain\Database\Attach\File::fromData` as a public interface and does not affect vanilla installations of October CMS since this method is not exposed or used by the system internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those who are unable to upgrade may apply with patch to their installation manually as a workaround.

NVD description · AI analysis pending
8.11%
  • octobercms october
CVE-2022-23655
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework.

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private keys. Users are advised to upgrade their installations to build 474 or v1.1.10. The only known workaround is to manually apply the patch (e3b455ad587282f0fbcb7763c6d9c3d000ca1e6a) which adds server signature validation.

NVD description · AI analysis pending
5.3<1%
  • octobercms october
CVE-2022-21705
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework.

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to bypass `cms.safe_mode` / `cms.enableSafeMode` in order to execute arbitrary code. This issue only affects admin panels that rely on safe mode and restricted permissions. To exploit this vulnerability, an attacker must first have access to the backend area. The issue has been patched in Build 474 (v1.0.474) and v1.1.10. Users unable to upgrade should apply https://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe to your installation manually.

NVD description · AI analysis pending
7.29%
  • octobercms october
CVE-2021-32650
+1 in the same advisory: …32649
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework.

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using the theme import feature. This will bypass the safe mode feature that prevents PHP execution in the CMS templates.The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to upgrade may apply the patch to their installation manually as a workaround.

NVD description · AI analysis pending
8.82% PoC
  • octobercms october
CVE-2021-41126
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework.

October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the backend using October CMS v2.0. The issue has been patched in v2.1.12 of the october/october package. There are no workarounds for this issue and all users should update.

NVD description · AI analysis pending
7.21%
  • octobercms october
CVE-2021-32648
Authentication Bypass in October CMS Password Reset Enables Account Takeover

October CMS, a content management system built on the Laravel PHP framework, contains an improper authentication flaw (CWE-287) in its october/system package: an attacker can initiate a password reset for any account and then submit a specially crafted request that bypasses the reset-code check, gaining access to that account without knowing the current password. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1: 9.1, critical), and takeover of a back-end administrator account would grant the attacker full control of the CMS's content, users, and configuration. Any October CMS deployment running october/system versions prior to Build 472 or v1.1.5 is affected. Exploitation is confirmed in the wild: CISA added CVE-2021-32648 to its Known Exploited Vulnerabilities Catalog on 2022-01-18 as part of a batch of 17 added flaws, requiring patching per vendor instructions, and EPSS assigns a 90.4% probability of exploitation within 30 days (100th percentile). CISA lists ransomware use as unknown, and no public proof-of-concept exploit is known.

Do: Update October CMS to Build 472 or v1.1.5 (or later) following the vendor's update instructions; because the flaw is in CISA's KEV, patching is required for federal agencies. Organizations that cannot patch immediately should restrict network access to the CMS back end and audit recent password-reset requests, back-end logins, and account modifications for signs of takeover, rotating credentials for any accounts with unexpected resets.

9.190% KEV
  • October CMS (october/system package) All versions prior to Build 472 and prior to v1.1.5; fixed in Build 472 and v1.1.5
large~ tens of thousands of installations (roughly 10,000-50,000 sites per public CMS usage trackers; a subset are internet-exposed) - estimate
CVE-2021-29487
octobercms in a CMS platform based on the Laravel PHP Framework.

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.

NVD description · AI analysis pending
7.4<1%
  • octobercms october
CVE-2021-21264
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework.

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend user with the `cms.manage_pages`, `cms.manage_layouts`, or `cms.manage_partials` permissions who would **normally** not be permitted to provide PHP code to be executed by the CMS due to `cms.enableSafeMode` being enabled is able to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This is not a problem for anyone that trusts their users with those permissions to normally write & manage PHP within the CMS by not having `cms.enableSafeMode` enabled, but would be a problem for anyone relying on `cms.enableSafeMode` to ensure that users with those permissions in production do not have access to write & execute arbitrary PHP. Issue has been patched in Build 472 (v1.0.472) and v1.1.2. As a workaround, apply https://github.com/octobercms/october/commit/f63519ff1e8d375df30deba63156a2fc97aa9ee7 to your installation manually if unable to upgrade to Build 472 or v1.1.2.

NVD description · AI analysis pending
5.2<1%
  • octobercms october
CVE-2021-21265
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework.

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly configured servers (i.e. the server routes any request, regardless of the HOST header to an October CMS instance) the potential exists for Host Header Poisoning attacks to succeed. This has been addressed in version 1.1.2 by adding a feature to allow a set of trusted hosts to be specified in the application. As a workaround one may set the configuration setting cms.linkPolicy to force.

NVD description · AI analysis pending
7.52%
  • octobercms october
CVE-2021-3311
An issue was discovered in October through build 471.

An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.

NVD description · AI analysis pending
9.83% PoC
  • octobercms october
CVE-2020-15246
+4 in the same advisory: …26231 …15249 …15247 …15248
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework.

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build 469 (v1.0.469) and v1.1.0.

NVD description · AI analysis pending
7.5
group max
2%
  • octobercms october
CVE-2020-15128
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to.

In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (nothing exploitable in the core project itself) had a higher chance of succeeding. Specifically, if your usage exposed a way for users to provide unfiltered user input and have it returned to them as an encrypted cookie (ex. storing a user provided search query in a cookie) they could then use the generated cookie in place of other more tightly controlled cookies; or if your usage exposed the plaintext version of an encrypted cookie at any point to the user they could theoretically provide encrypted content from your application back to it as an encrypted cookie and force the framework to decrypt it for them. Issue has been fixed in build 468 (v1.0.468).

NVD description · AI analysis pending
6.3<1%
  • octobercms october
CVE-2020-11083
In October from version 1.0.319 and before version 1.0.466, a user with access to a markdown FormWidget that stores data persistently could create a stored XSS

In October from version 1.0.319 and before version 1.0.466, a user with access to a markdown FormWidget that stores data persistently could create a stored XSS attack against themselves and any other users with access to the generated HTML from the field. This has been fixed in 1.0.466. For users of the RainLab.Blog plugin, this has also been fixed in 1.4.1.

NVD description · AI analysis pending
4.81% PoC ×2
  • octobercms october
CVE-2020-4061
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successf

In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.

NVD description · AI analysis pending
5.4<1% PoC
  • octobercms october
CVE-2020-11094
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including

The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a problem if the plugin is ever enabled on a system that is open to untrusted users as the potential exists for them to use this feature to view all requests being made to the application and obtain sensitive information from those requests. There even exists the potential for account takeovers of authenticated users by non-authenticated public users, which would then lead to a number of other potential issues as an attacker could theoretically get full access to the system if the required conditions existed. Issue has been patched in v3.1.0 by locking down access to the debugbar to all users; it now requires an authenticated backend user with a specifically enabled permission before it is even usable, and the feature that allows access to stored request information is restricted behind a different permission that's more restrictive.

NVD description · AI analysis pending
9.81%
  • octobercms debugbar
CVE-2020-5299
+4 in the same advisory: …5295 …5296 …5298 …5297
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually b

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `ImportExportController` could potentially introduce a CSV injection into the data to cause the generated CSV export file to be malicious. This requires attackers to achieve the following before a successful attack can be completed: 1. Have found a vulnerability in the victims spreadsheet software of choice. 2. Control data that would potentially be exported through the `ImportExportController` by a theoretical victim. 3. Convince the victim to export above data as a CSV and run it in vulnerable spreadsheet software while also bypassing any sanity checks by said software. Issue has been patched in Build 466 (v1.0.466).

NVD description · AI analysis pending
5.1
group max
1%
  • octobercms october
CVE-2018-1999009
+1 in the same advisory: …1999008
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.

NVD description · AI analysis pending
8.1
group max
2%
  • octobercms october
CVE-2018-7198
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.

October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.

NVD description · AI analysis pending
6.12% PoC
  • octobercms october
CVE-2017-16941
October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a

October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a theme ZIP archive from /backend/cms/themes, and then uploading and importing a modified archive with two new files: a .php file and a .htaccess file. NOTE: the vendor says "I don't think [an attacker able to login to the system under an account that has access to manage/upload themes] is a threat model that we need to be considering.

NVD description · AI analysis pending
8.82%
  • octobercms october
CVE-2017-1000196
+1 in the same advisory: …1000197
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the

October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.

NVD description · AI analysis pending
9.82%
  • octobercms october