OVERVIEW CVE-2026-24906 is a Stored Cross-Site Scripting (XSS) vulnerability affecting October CMS versions prior to 3.7.14 and 4.1.10. The flaw exists in the Backend Editor Settings, specifically in the Markup Classes fields used for paragraph, inline, and table styles. These fields fail to sanitize input to valid CSS class name characters, allowing malicious scripts to be stored and later executed when users interact with the RichEditor. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.4 (Medium) with a network-accessible attack vector requiring low complexity. Exploitation demands authenticated backend access with editor settings permissions and user interaction (when a user opens a RichEditor). The impact is limited to confidentiality and integrity compromise with no availability impact. However, the severity escalates significantly in scenarios where a superuser opens a RichEditor, as this could enable privilege escalation attacks against high-privileged accounts. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities (KEV) catalog, and the Hot List status is inactive. The EPSS score of 0.00011 indicates minimal probability of exploitation, placing it in the lower percentile of all CVEs. Community attention remains limited at this time. Organizations should apply patches to versions 3.7.14 and 4.1.10 or restrict editor settings permissions to fully trusted administrators as an interim mitigation measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.7.13CPE matchmatch criteria | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* | ||
>= 4.0.0, <= 4.1.9CPE matchmatch criteria | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.