All vulnerabilities
62 / 62
Sort
9.1
CVE-2021-32648CVE KEV
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the oc…
2021-01-01KEV
EPSS90.4%
pct 99
7.2
CVE-2017-1000119CVE
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resu…
2017-01-01
EPSS61.3%
pct 99
7.2
CVE-2022-21705CVE
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versio…
2022-01-01
EPSS8.7%
pct 94
4.9
CVE-2020-5295CVE
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an a…
2020-01-01
EPSS7.4%
pct 93
5.4
CVE-2017-15284CVE
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged …
2017-01-01
EPSS4.0%
pct 89
9.8
CVE-2021-3311CVE
An issue was discovered in October through build 471. It reactivates an old session ID (which h…
2021-01-01Pre-auth
EPSS2.9%
pct 85
6.1
CVE-2018-7198CVE
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
2018-01-01Pre-auth
EPSS2.5%
pct 82
8.1
CVE-2018-1999009CVE
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules…
2018-01-01Pre-auth
EPSS2.4%
pct 81
8.8
CVE-2021-32650CVE
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP …
2021-01-01
EPSS2.1%
pct 79
8.8
CVE-2017-16244CVE
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validat…
2017-01-01Pre-auth
EPSS2.0%
pct 77
9.8
CVE-2017-1000196CVE
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality re…
2017-01-01Pre-auth
EPSS1.9%
pct 77
4.3
CVE-2015-5612CVE
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote att…
2015-01-01
EPSS1.8%
pct 76
7.5
CVE-2020-15246CVE
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In…
2020-01-01Pre-auth
EPSS1.7%
pct 73
8.8
CVE-2017-16941CVE
October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote au…
2017-01-01
EPSS1.6%
pct 71
7.5
CVE-2017-1000195CVE
October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulti…
2017-01-01Pre-auth
EPSS1.5%
pct 71
7.5
CVE-2021-21265CVE
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In…
2021-01-01Pre-auth
EPSS1.5%
pct 71
4.9
CVE-2020-5296CVE
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an a…
2020-01-01
EPSS1.4%
pct 69
8.8
CVE-2021-32649CVE
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP …
2021-01-01
EPSS1.3%
pct 67
9.8
CVE-2017-1000194CVE
October CMS build 412 is vulnerable to Apache configuration modification via file upload functi…
2017-01-01Pre-auth
EPSS1.2%
pct 65
9.8
CVE-2017-1000197CVE
October CMS build 412 is vulnerable to file path modification in asset move functionality resul…
2017-01-01Pre-auth
EPSS1.2%
pct 64
2.7
CVE-2020-5297CVE
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an a…
2020-01-01
EPSS1.2%
pct 63
4.8
CVE-2020-11083CVE
In October from version 1.0.319 and before version 1.0.466, a user with access to a markdown Fo…
2020-01-01
EPSS1.1%
pct 62
8.1
CVE-2022-24800CVE
October/System is the system module for October CMS, a self-hosted CMS platform based on the La…
2022-01-01Pre-auth
EPSS1.1%
pct 62
7.2
CVE-2021-41126CVE
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Fram…
2021-01-01
EPSS1.1%
pct 59
9.8
CVE-2020-11094CVE
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all r…
2020-01-01Pre-auth
EPSS1.0%
pct 59
6.1
CVE-2017-1000193CVE
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resultin…
2017-01-01Pre-auth
EPSS1.0%
pct 58
5.1
CVE-2020-5299CVE
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any …
2020-01-01
EPSS1.0%
pct 58
5.4
CVE-2015-5613CVE
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote att…
2015-01-01
EPSS0.9%
pct 55
4.8
CVE-2020-5298CVE
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a us…
2020-01-01
EPSS0.9%
pct 55
7.4
CVE-2021-29487CVE
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the oc…
2021-01-01Pre-auth
EPSS0.9%
pct 54
9.1
CVE-2023-44382CVE
October is a Content Management System (CMS) and web platform to assist with development workfl…
2023-01-01
EPSS0.9%
pct 54
7.2
CVE-2022-35944CVE
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Fram…
2022-01-01
EPSS0.9%
pct 53
5.4
CVE-2020-4061CVE
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicio…
2020-01-01
EPSS0.8%
pct 52
6.3
CVE-2020-15128CVE
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the …
2020-01-01
EPSS0.7%
pct 47
5.3
CVE-2022-23655CVE
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions …
2022-01-01Pre-auth
EPSS0.6%
pct 44
5.4
CVE-2018-1999008CVE
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in t…
2018-01-01
EPSS0.5%
pct 39
4.9
CVE-2023-44381CVE
October is a Content Management System (CMS) and web platform to assist with development workfl…
2023-01-01
EPSS0.5%
pct 39
5.4
CVE-2023-37692CVE
An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitr…
2023-01-01
EPSS0.5%
pct 38
4.7
CVE-2024-45962CVE
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious …
2024-01-01Pre-auth
EPSS0.5%
pct 36
5.4
CVE-2020-15249CVE
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In…
2020-01-01
EPSS0.5%
pct 36
Select a vulnerability on the left to open the preview.