MEDIUM6.1Packagist
GHSA-55mm-5399-7r63· CVE-2020-15128Reliance on Cookies without validation in OctoberCMS
Modified: 9/10/2026
package
pkg:packagist/october/rain
Reliance on Cookies without validation in OctoberCMS
Modified: 9/10/2026
October CMS Session ID not invalidated after logout
Modified: 2/16/2024
October Rain has Environment Variable Exfiltration via INI Parser Interpolation
Modified: 5/8/2026
October Rain has Stored XSS via SVG Filter Bypass
Modified: 5/8/2026
OctoberCMS Cross-Site Scripting
Modified: 4/23/2025
October Rain has a Twig Sandbox Bypass via Collection Methods
Modified: 4/14/2026