Octobercms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 62
    Known Exploited: 1
    5
    Critical Level Threats
    14
    High Level Threats
    35
    Medium Level Threats
    8
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-29179

    October: Editor Sub-Permission Bypass for Asset and Blueprint File Operations

    Last Modified: Apr 22, 2026
    Published: Apr 21, 2026

    CVE-2026-27937

    October: Reflected XSS via DataTable Form Widget

    Last Modified: Apr 22, 2026
    Published: Apr 21, 2026

    CVE-2026-26274

    October: Safe Mode Bypass via Twig Database Write Operations

    Last Modified: Apr 22, 2026
    Published: Apr 21, 2026

    CVE-2026-26067

    October: Safe Mode Bypass via CSS Preprocessor Compilers

    Last Modified: Apr 22, 2026
    Published: Apr 21, 2026

    CVE-2026-25133

    October CMS has Stored XSS via SVG Filter Bypass

    Last Modified: Apr 23, 2026
    Published: Apr 14, 2026
    Items Per Page