Vulnerabilities > Octobercms > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-17 CVE-2017-1000193 Cross-site Scripting vulnerability in Octobercms October
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
network
low complexity
octobercms CWE-79
6.1
2017-10-12 CVE-2017-15284 Cross-site Scripting vulnerability in Octobercms October 1.0.425
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile.
network
low complexity
octobercms CWE-79
5.4
2017-09-28 CVE-2015-5613 Cross-site Scripting vulnerability in Octobercms October
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving a file title, a different vulnerability than CVE-2015-5612.
network
low complexity
octobercms CWE-79
5.4