cbcvebase.

October System vulnerabilities

23 known vulnerabilities affecting october/system.

Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH6MEDIUM9LOW5

Vulnerabilities

Page 2 of 2
CVE-2024-24764P4LOW≥ 3.2, < 3.5.152024-06-26
CVE-2024-24764 [LOW] CWE-601 October System module has an Open Redirect for Administrator Accounts October System module has an Open Redirect for Administrator Accounts ### Impact This advisory affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability assumes a trusted
ghsaosv
CVE-2026-29179P4LOW≥ 4.0.0, < 4.1.16≥ 0, < 3.7.162026-04-21
CVE-2026-29179 [LOW] CWE-863 October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations Fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend users who were explicitly granted `editor` access but had `editor.cms_assets` or `editor.tailor_blueprints` specifically withheld, an uncommon per
ghsa
CVE-2026-27937P4LOW≥ 0, < 3.7.16≥ 4.0.02026-04-21
CVE-2026-27937 [LOW] CWE-79 October CMS: Reflected XSS via DataTable Form Widget October CMS: Reflected XSS via DataTable Form Widget A reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. ### Impact - Reflected XSS only, no stored/persistent component - The backend URL prefix is customizable and must be known or guessed by the attacker - Requires an authenticated backend user to v
ghsa
October System vulnerabilities | cvebase