cvedb.io
CVE-2025-61676
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2026-01-10T04:16:00.850 · Last modified 2026-06-17T09:50:45.817

Summary

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

Affected products

octobercms — october

Does this affect you?

Add your gear to cvedb and we'll alert you only when octobercms ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.