CVE-2025-61674

MEDIUM

October CMS < 3.7.13 and < 4.0.12 - Stored Cross-Site Scripting via Markup Styles Stylesheet Input

Title source: llm
STIX 2.1

Description

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permission could inject malicious HTML/JS into the stylesheet input at Markup Styles. A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0018
EPSS Percentile 8.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
october/system 0 - 3.7.13Packagist
octobercms/october < 3.17.3
Published Jan 10, 2026
Tracked Since Feb 18, 2026