System module for October CMS
october/[email protected] low health (33/100) — consider alternatives
Update to >= 4.0.12 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2026-26067 | October CMS has Safe Mode Bypass via CSS Preprocessor Compilers | 4.1.10 |
| medium | CVE-2026-24906 | October CMS has Stored XSS in Backend Editor Markup Classes | 3.7.14 |
| low | CVE-2024-51991 | October CMS Allows Unprotected SVG Rename in Media Manager | 3.7.5 |
| medium | CVE-2025-61674 | October CMS Vulnerable to Stored XSS via Editor and Branding Styles | 4.0.12 |
| medium | CVE-2026-24907 | October CMS has Stored XSS in Event Log Mail Preview | 3.7.14 |
| low | CVE-2026-27937 | October CMS: Reflected XSS via DataTable Form Widget | 3.7.16 |
| low | CVE-2026-29179 | October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations | 3.7.16 |
| medium | CVE-2025-61676 | October CMS Vulnerable to Stored XSS via Branding Styles | 4.0.12 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/composer/october/systemLast updated · 2022-02-20T01:54:45+00:00