October/system
This hub aggregates every CVE we track for October/system, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
1
Critical
7
High
1
In CISA KEV
Severity distribution
HIGH7MEDIUM7LOW2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
2
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting October/system.
- CVE-2025-61674October CMS Vulnerable to Stored XSS via Editor and Branding Styles6.1
- CVE-2025-61676October CMS Vulnerable to Stored XSS via Branding Styles6.1
- CVE-2024-51991October CMS Allows Unprotected SVG Rename in Media Manager4.9
- CVE-2024-25637Reflected XSS via X-October-Request-Handler Header3.1
- CVE-2024-24764October Open Redirect for Administrator Accounts3.5
- CVE-2023-44381October CMS safe mode bypass using Page template injection4.9
- CVE-2023-44382October CMS safe mode bypass using Twig sandbox escape9.1
- CVE-2023-44383October CMS stored XSS by authenticated backend user with improper configuration5.4
- CVE-2022-35944October CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)6.2
- CVE-2022-24800Race Condition in October CMS upload process8.1
- CVE-2022-23655Missing server signature validation in OctoberCMS4.8
- CVE-2022-21705Authenticated remote code execution in octobercms7.2
- CVE-2021-32649Authenticated file write leads to remote code execution in october/system8.8
- CVE-2021-32650Arbitrary code execution in october/system8.8
- CVE-2021-41126Deleted Admin Can Sign In to Admin Interface7.2
Product normalization is registry-driven with AI assist and human review. How it works