octobercms has 4 CVEs on record. 2 were published in the last 90 days. The median CVSS is 4.0 (medium). Most affected products: october (3), system (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 2
Worst active — by depth score
CVE-2026-25125Medium· 4.9October is a Content Management System (CMS) and web platform27CVE-2026-25133Medium· 4.8October is a Content Management System (CMS) and web platform26CVE-2026-49400Low· 3.3October System provides the system module for October Content Management System18CVE-2026-46696Low· 3.3October System provides the system module for October Content Management System18
octobercms vulnerabilities
CVEs affecting octobercms, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-49400Low· 3.3October System provides the system module for October Content Management System
October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserial…
CVE-2026-46696Low· 3.3October System provides the system module for October Content Management System
October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. …
CVE-2026-25133Medium· 4.8October is a Content Management System (CMS) and web platform
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler att…
CVE-2026-25125Medium· 4.9October is a Content Management System (CMS) and web platform
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports …