LOW3.7Packagist
GHSA-3pc2-fm7p-q2vg· CVE-2020-4061Cross-site Scripting in October
Modified: 7/8/2026
package
pkg:packagist/october/backend
Cross-site Scripting in October
Modified: 7/8/2026
Potential CSV Injection vector in OctoberCMS
Modified: 7/8/2026
Stored XSS by authenticated backend user with access to upload files
Modified: 7/8/2026
Reflected XSS when importing CSV in OctoberCMS
Modified: 7/8/2026
Privilege escalation by backend users assigned to the default "Publisher" system role
Modified: 7/8/2026
Stored XSS in October
Modified: 9/10/2026
October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers
Modified: 7/8/2026