Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Octobercms

First CVE: Sep 4, 2015Active for: 11 yearsTotal CVEs: 58
57.4
VTI Score
TOP TARGET

October CMS is a PHP-based content-management platform whose vulnerability profile reflects the risks inherent in web-application frameworks that handle user input and dynamic code execution. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity and a consistent tendency toward public exploit availability, making timely patching essential for deployed instances. The exposure recurs across the October core product and associated components like DebugBar, concentrating in weakness classes including cross-site scripting, code injection, unrestricted file uploads, and improper authentication—all characteristic of web frameworks that mediate between untrusted user data and server-side execution. Defenders should treat October CMS advisories as high-priority, inventory deployed instances for their exposure surface (particularly plugin ecosystems), and maintain current patches; live severity and public-exploit figures are shown alongside this summary.

FAUCET AI Generated
58
Total CVEs
More Total CVEs than 99% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
1.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Octobercms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2015
10 years ago
Most Recent CVE
Apr 14, 2026
103 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (58 CVEs).

58 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-32648CRITICAL
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain
Aug 26, 20219.197YESYES
CVE-2017-1000119HIGH
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
Oct 5, 20177.274NOYES
CVE-2022-21705HIGH
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with
Feb 23, 20227.239NOYES
CVE-2017-16244HIGH
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take o
Nov 1, 20178.838NOYES
CVE-2021-3311CRITICAL
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the inte
Feb 5, 20219.831NONO
CVE-2017-15284MEDIUM
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. W
Oct 12, 20175.431NOYES
CVE-2018-7198MEDIUM
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
Feb 18, 20186.130NOYES
CVE-2017-1000196CRITICAL
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.
Nov 17, 20179.829NONO
CVE-2021-32650HIGH
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backen
Jan 14, 20228.828NONO
CVE-2021-32649HIGH
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and
Jan 14, 20228.828NONO
View all 58 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products58 CVEs
60%
26%
12%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (8.6%)
Network52 (89.7%)
Unknown1 (1.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low51 (87.9%)
High6 (10.3%)
Unknown1 (1.7%)
User Interaction
None30 (51.7%)
Unknown1 (1.7%)
Required27 (46.6%)
Privileges Required
Low16 (27.6%)
High23 (39.7%)
None18 (31.0%)
Unknown1 (1.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (58 CVEs).

CISA KEV
1 CVE
1.7% of CVEs· 99th percentile
Metasploit
1 CVE
1.7% of CVEs· 97th percentile
Nuclei
2 CVEs
3.4% of CVEs· 95th percentile
ExploitDB
5 CVEs
8.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Octobercms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Octobercms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Octobercms's Products

View all 2 CNAs →

Top CWEs