Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-61676

Опубликовано: 10 янв. 2026
Источник: nvd
CVSS3: 6.1
CVSS3: 4.8
EPSS Низкий

Описание

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
Версия до 3.7.13 (исключая)
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.12 (исключая)

EPSS

Процентиль: 12%
0.0004
Низкий

6.1 Medium

CVSS3

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
29 дней назад

October CMS Vulnerable to Stored XSS via Branding Styles

EPSS

Процентиль: 12%
0.0004
Низкий

6.1 Medium

CVSS3

4.8 Medium

CVSS3

Дефекты

CWE-79