Skip to main content

Vendor/product archive

octobercms / october CVEs

Beta · best-effort

57 CVEs tagged to octobercms / october5 Critical, 14 High, 31 Medium, 7 Low, 0 Unrated.

CVE-2017-1000194

Published Nov 17, 2017

October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000193

Published Nov 17, 2017

October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16244

Published Nov 1, 2017

Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15284

Published Oct 12, 2017

Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000119

Published Oct 5, 2017

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5613

Published Sep 28, 2017

Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving a file title, a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5612

Published Sep 4, 2015

Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-57 of 57 CVEsPage 3 of 3