Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24906

19
FAUCET Score

OVERVIEW CVE-2026-24906 is a Stored Cross-Site Scripting (XSS) vulnerability affecting October CMS versions prior to 3.7.14 and 4.1.10. The flaw exists in the Backend Editor Settings, specifically in the Markup Classes fields used for paragraph, inline, and table styles. These fields fail to sanitize input to valid CSS class name characters, allowing malicious scripts to be stored and later executed when users interact with the RichEditor. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.4 (Medium) with a network-accessible attack vector requiring low complexity. Exploitation demands authenticated backend access with editor settings permissions and user interaction (when a user opens a RichEditor). The impact is limited to confidentiality and integrity compromise with no availability impact. However, the severity escalates significantly in scenarios where a superuser opens a RichEditor, as this could enable privilege escalation attacks against high-privileged accounts. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities (KEV) catalog, and the Hot List status is inactive. The EPSS score of 0.00011 indicates minimal probability of exploitation, placing it in the lower percentile of all CVEs. Community attention remains limited at this time. Organizations should apply patches to versions 3.7.14 and 4.1.10 or restrict editor settings permissions to fully trusted administrators as an interim mitigation measure.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.7.13CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
>= 4.0.0, <= 4.1.9CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 21st percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: october/systemFixed in: 4.1.10
composerpatch availablevia ghsa
Product: october/systemFixed in: 3.7.14
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-6qmh-j78v-ffp7medium

October CMS has Stored XSS in Backend Editor Markup Classes

Apr 14, 2026

References

github.com / octobercms/october/security/advisories/GHSA-6qmh-j78v-ffp7
Vendor Advisory