Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-11083

16
FAUCET Score

CVE-2020-11083 describes a stored Cross-Site Scripting (XSS) vulnerability affecting October CMS versions 1.0.319 through 1.0.465, and the RainLab.Blog plugin prior to version 1.4.1. An authenticated user with access to a markdown FormWidget could inject malicious scripts that would execute when other users viewed the generated HTML. This vulnerability has a CVSS score of 4.8 (Medium), indicating a network-based attack requiring high privileges and user interaction, with potential for low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.319, < 1.0.466CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.5LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
0.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.15%
Probability of exploitation in next 30 days
EPSS Percentile
63.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0115 is in the 95th percentile among its peer group of 4,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: october/backendFixed in: 1.0.466
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-w4pj-7p68-3vgvlow

Stored XSS in October

Aug 5, 2020

References

packetstormsecurity.com / files/158730/October-CMS-Build-465-XSS-File-Read-File-Deletion-CSV-Injection.html
ExploitThird Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2020/Aug/2
ExploitMailing ListThird Party Advisory
github.com / octobercms/october/commit/9ecfb4867baae14a0d3f99f5b5c1e8a979ae8746
PatchThird Party Advisory
github.com / octobercms/october/security/advisories/GHSA-w4pj-7p68-3vgv
PatchThird Party Advisory
github.com / rainlab/blog-plugin/commit/6ae19a6e16ef3ba730692bc899851342c858bb94
PatchThird Party Advisory