VulnSea

octobercms has 4 CVEs on record. 2 were published in the last 90 days. The median CVSS is 4.0 (medium). Most affected products: october (3), system (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
4.0
Publish → KEV
—
Last 90 days
2 prev 2

Products

  • october 3
  • system 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

octobercms vulnerabilities

CVEs affecting octobercms, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-49400Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserial…

▾ Sunlitoctobercms · octoberEPSS 0.18%via NVD
CVE-2026-46696Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. …

▾ Sunlitoctobercms · systemEPSS 0.22%via NVD
CVE-2026-25133Medium· 4.8
5mo ago

October is a Content Management System (CMS) and web platform

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler att…

▾ Sunlitoctobercms · octoberEPSS 0.22%via NVD
CVE-2026-25125Medium· 4.9
5mo ago

October is a Content Management System (CMS) and web platform

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports …

▾ Sunlitoctobercms · octoberEPSS 0.33%via NVD
octobercms vulnerabilities (CVEs) · VulnSea