Security: octobercms/october
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stored XSS via Editor SettingsGHSA-gxxc-m74c-f48x published
Jan 9, 2026 by daftspunkModerate -
Unprotected SVG Rename in Media ManagerGHSA-96hh-8hx5-cpw7 published
May 3, 2025 by daftspunkLow -
Reflected XSS via X-October-Request-Handler HeaderGHSA-rjw8-v7rr-r563 published
Jun 25, 2024 by daftspunkLow -
Open Redirect for Administrator AccountsGHSA-v2vf-jv88-3fp5 published
Jun 25, 2024 by daftspunkLow -
Safe mode bypass using Twig sandbox escapeGHSA-p8q3-h652-65vx published
Nov 29, 2023 by daftspunkModerate -
Safe mode bypass using Page template injectionGHSA-q22j-5r3g-9hmh published
Nov 29, 2023 by daftspunkModerate -
Stored XSS by authenticated backend user with improper configurationGHSA-rvx8-p3xp-fj3p published
Nov 29, 2023 by daftspunkLow -
Safe Mode bypass leads to authenticated Remote Code ExecutionGHSA-x4q7-m6fp-4v9v published
Oct 13, 2022 by daftspunkModerate -
RCE via race condition in upload processGHSA-8v7h-cpc2-r8jp published
Jul 12, 2022 by daftspunkModerate -
Compromised gateway causes data breachGHSA-53m6-44rc-h2q5 published
Feb 23, 2022 by daftspunkModerate