Octobercms
Octobercms October: vulnerabilidades y CVE
Octobercms October tiene 61 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE61
Últimos 12 meses11
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-32648 | Crítica (9.1) | 90% | ⚠ Explotación activa | 26 ago 2021 | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-29179 | Baja (3.3) | 0.23% | — | 21 abr 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor… |
| CVE-2026-27937 | Baja (3.1) | 0.23% | — | 21 abr 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was… |
| CVE-2026-26274 | Media (6.6) | 0.39% | — | 21 abr 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is… |
| CVE-2026-26067 | Media (4.9) | 0.42% | — | 21 abr 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with… |
| CVE-2026-25133 | Media (4.8) | 0.22% | — | 14 abr 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip… |
| CVE-2026-25125 | Media (4.9) | 0.33% | — | 14 abr 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string()… |
| CVE-2026-24907 | Media (5.1) | 0.20% | — | 14 abr 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. When viewing logged… |
| CVE-2026-24906 | Media (5.1) | 0.25% | — | 14 abr 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields… |
| CVE-2026-22692 | Media (6.8) | 0.40% | — | 14 abr 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE).… |
| CVE-2025-61676 | Media (4.8) | 0.27% | — | 10 ene 2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the… |
| CVE-2025-61674 | Media (4.8) | 0.27% | — | 10 ene 2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the… |
| CVE-2024-51991 | Baja (1.1) | 0.38% | — | 5 may 2025 | October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This… |
| CVE-2024-45962 | Media (4.7) | 0.51% | — | 2 oct 2024 | October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting… |
| CVE-2024-25837 | Media (5.4) | 0.24% | — | 16 ago 2024 | A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section. |
| CVE-2024-25637 | Media (5.4) | 0.26% | — | 26 jun 2024 | October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact… |
| CVE-2024-24764 | Media (4.8) | 0.27% | — | 26 jun 2024 | October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page… |
| CVE-2023-25365 | Alta (7.8) | 0.36% | — | 8 feb 2024 | Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3 |
| CVE-2023-44382 | Crítica (9.1) | 0.87% | — | 1 dic 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions… |
| CVE-2023-44381 | Media (4.9) | 0.51% | — | 1 dic 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions… |
| CVE-2023-44383 | Media (5.4) | 0.41% | — | 29 nov 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and… |
| CVE-2023-43876 | Media (5.4) | 0.48% | — | 28 sept 2023 | A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field. |
| CVE-2023-37692 | Media (5.4) | 0.52% | — | 26 jul 2023 | An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file. |
| CVE-2022-35944 | Alta (7.2) | 0.94% | — | 13 oct 2022 | October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing… |
| CVE-2022-24800 | Alta (8.1) | 1.5% | — | 12 jul 2022 | October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own… |
| CVE-2022-23655 | Media (5.3) | 0.64% | — | 24 feb 2022 | Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to… |
| CVE-2022-21705 | Alta (7.2) | 8.6% | — | 23 feb 2022 | Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and… |
| CVE-2021-32650 | Alta (8.8) | 2.1% | — | 14 ene 2022 | October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using… |
| CVE-2021-32649 | Alta (8.8) | 1.3% | — | 14 ene 2022 | October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the… |
| CVE-2021-41126 | Alta (7.2) | 1.1% | — | 6 oct 2021 | October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the… |
| CVE-2021-32648 | Crítica (9.1) | 90% | ⚠ Explotación activa | 26 ago 2021 | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.