October CMS Cross-Site Scripting Vulnerability in Backend Configuration Forms

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in October CMS versions 3.7.12 and prior, as well as 4.0.11 and prior. The issue resides in the backend configuration forms, specifically within the Editor Settings Markup Styles section. Users with the Global Editor Settings permission could inject malicious HTML or JavaScript into the stylesheet input. This crafted input could escape the intended <style> context, enabling arbitrary script execution across backend pages for all users.

Impact

Exploitation of this vulnerability leads to persistent cross-site scripting across the backend interface. It can be exploited by lower-privileged accounts with Global Editor Settings permissions, potentially allowing privilege escalation, session hijacking, and execution of unauthorized actions in victim sessions.

Remediation

Users are advised to upgrade to October CMS versions 3.7.13 or 4.0.12, where this vulnerability has been patched. For those unable to upgrade immediately, it is recommended to restrict Global Editor Settings permissions to trusted administrators only.

Added: Jan 10, 2026, 4:23 AM
Updated: Jan 10, 2026, 4:23 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
4.7
remediation
7.9
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.