October CMS is a PHP-based content-management platform whose vulnerability profile reflects the risks inherent in web-application frameworks that handle user input and dynamic code execution. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity and a consistent tendency toward public exploit availability, making timely patching essential for deployed instances. The exposure recurs across the October core product and associated components like DebugBar, concentrating in weakness classes including cross-site scripting, code injection, unrestricted file uploads, and improper authentication—all characteristic of web frameworks that mediate between untrusted user data and server-side execution. Defenders should treat October CMS advisories as high-priority, inventory deployed instances for their exposure surface (particularly plugin ecosystems), and maintain current patches; live severity and public-exploit figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Octobercms over time
Signals from CVEs in this vendor scope (58 CVEs).
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32648CRITICAL octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain | Aug 26, 2021 | 9.1 | 97 | YES | YES |
CVE-2017-1000119HIGH October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server. | Oct 5, 2017 | 7.2 | 74 | NO | YES |
CVE-2022-21705HIGH Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with | Feb 23, 2022 | 7.2 | 39 | NO | YES |
CVE-2017-16244HIGH Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take o | Nov 1, 2017 | 8.8 | 38 | NO | YES |
CVE-2021-3311CRITICAL An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the inte | Feb 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2017-15284MEDIUM Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. W | Oct 12, 2017 | 5.4 | 31 | NO | YES |
CVE-2018-7198MEDIUM October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page. | Feb 18, 2018 | 6.1 | 30 | NO | YES |
CVE-2017-1000196CRITICAL October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server. | Nov 17, 2017 | 9.8 | 29 | NO | NO |
CVE-2021-32650HIGH October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backen | Jan 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-32649HIGH October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and | Jan 14, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (58 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Octobercms.
Media articles that mention a CVE ID that affects a product developed by Octobercms — matched by CVE ID, not by vendor name.