October
This hub aggregates every CVE we track for October, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
61
CVEs tracked
5
Critical
14
High
1
In CISA KEV
Severity distribution
MEDIUM34HIGH14LOW8CRITICAL5
Monthly trend
0
1
0
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
2
0
0
9
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting October.
- CVE-2026-29179October: Editor Sub-Permission Bypass for Asset and Blueprint File Operations3.3
- CVE-2026-27937October: Reflected XSS via DataTable Form Widget3.1
- CVE-2026-26274October: Safe Mode Bypass via Twig Database Write Operations6.6
- CVE-2026-26067October: Safe Mode Bypass via CSS Preprocessor Compilers4.9
- CVE-2026-25133October CMS has Stored XSS via SVG Filter Bypass4.8
- CVE-2026-25125October CMS: Environment Variable Exfiltration via INI Parser Interpolation4.9
- CVE-2026-24907October CMS has Stored XSS via Event Log Mail Preview5.4
- CVE-2026-24906October CMS has Stored XSS in its Backend Editor Markup Classes5.4
- CVE-2026-22692October CMS: Twig Sandbox Bypass via Collection Methods4.9
- CVE-2025-61674October CMS Vulnerable to Stored XSS via Editor and Branding Styles6.1
- CVE-2025-61676October CMS Vulnerable to Stored XSS via Branding Styles6.1
- CVE-2024-51991October CMS Allows Unprotected SVG Rename in Media Manager4.9
- CVE-2024-45962October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cro...4.7
- CVE-2024-25837A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments se...5.4
- CVE-2024-25637Reflected XSS via X-October-Request-Handler Header3.1
Product normalization is registry-driven with AI assist and human review. How it works