CVE security advisories and vulnerability history for october by octobercms.
61
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
15
Public exploits
With known exploit
5.5
Avg CVSS
2015–2026
Last updated
Overview
octobercms october has 61 published CVE records since 2015, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 15 have a known public exploit. The average CVSS base score across scored CVEs is 5.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting octobercms october, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of octobercms october's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High8
Medium25
Low9
17 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of octobercms october's CVEs is confirmed exploited in the wild.
Public exploits
15
15 of octobercms october's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every octobercms october version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about octobercms october vulnerabilities.
How many CVEs does octobercms october have?
octobercms october has 61 published CVE records since 2015.
How many octobercms october CVEs are in CISA KEV?
Yes — 1 of octobercms october's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for octobercms october vulnerabilities?
Yes — 15 of octobercms october's CVEs have a known public exploit.
Which versions of octobercms october are affected?
321 distinct octobercms october versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in octobercms october CVEs?
octobercms october's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-863 (Incorrect Authorization), CWE-862 (Missing Authorization), CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')).
How many critical octobercms october vulnerabilities are there?
octobercms october has 2 critical and 8 high-severity CVEs.
What is the average severity of octobercms october CVEs?
The average CVSS base score across octobercms october's scored CVEs is 5.5.