Ecosyste.ms: OpenCollective
An open API service for software projects hosted on Open Collective.
OctoberCMS
Free, open-source, self-hosted CMS platform based on the Laravel PHP Framework.
Collective -
Host: opensource -
https://opencollective.com/octobercms
- Website: https://octobercms.com/
- Code: https://github.com/octobercms/october
Low
Ecosystems: packagist
Packages: october/system
Source: github
Published: 6 months ago
october: GSA_kwCzR0hTQS12MnZmLWp2ODgtM2ZwNc4AA9Xp
October System module has an Open Redirect for Administrator AccountsEcosystems: packagist
Packages: october/system
Source: github
Published: 6 months ago
Low
Ecosystems: packagist
Packages: october/system
Source: github
Published: 6 months ago
october: GSA_kwCzR0hTQS1yanc4LXY3cnItcjU2M84AA9Xl
October System module has a Reflected XSS via X-October-Request-Handler HeaderEcosystems: packagist
Packages: october/system
Source: github
Published: 6 months ago
Moderate
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
october: GSA_kwCzR0hTQS1ydng4LXAzeHAtZmozcM4AA3a4
October CMS stored XSS by authenticated backend user with improper configurationEcosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
Critical
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
october: GSA_kwCzR0hTQS1wOHEzLWg2NTItNjV2eM4AA3a2
October CMS safe mode bypass using Twig sandbox escapeEcosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
october: GSA_kwCzR0hTQS1xMjJqLTVyM2ctOWhtaM4AA3a1
October CMS safe mode bypass using Page template injectionEcosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 2 years ago
october: GSA_kwCzR0hTQS14NHE3LW02ZnAtNHY5ds4AAvUA
October CMS Safe Mode bypass leads to authenticated Remote Code ExecutionEcosystems: packagist
Packages: october/system
Source: github
Published: about 2 years ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: over 2 years ago
october: GSA_kwCzR0hTQS04djdoLWNwYzItcjhqcM4AAtX7
October CMS upload process vulnerable to RCE via Race ConditionEcosystems: packagist
Packages: october/system
Source: github
Published: over 2 years ago
Moderate
Ecosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
october: GSA_kwCzR0hTQS05aHE4LXYyamMtcWo0cs4AAdqt
October CMS XSS In Caption Tag of ProfileEcosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
High
Ecosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
october: GSA_kwCzR0hTQS12bTZyLTRwNHYtMjMyeM4AAQVx
October CMS CSRFEcosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
Moderate
Ecosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
october: GSA_kwCzR0hTQS0zcDZjLTl4aG0tOHg3aM4AAQVR
October CMS XSSEcosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
Critical
Ecosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
october: GSA_kwCzR0hTQS04dmg2LTh3NzYtdjZtM84AAQVU
October CMS File Upload VulnerabilityEcosystems: packagist
Packages: october/october
Source: github
Published: over 2 years ago
Moderate
Ecosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
october: GSA_kwCzR0hTQS01M202LTQ0cmMtaDJxNc0uRQ
Missing server signature validation in OctoberCMSEcosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
october: GSA_kwCzR0hTQS03OWp3LTJmNDYtd3YyMs0uLg
Authenticated remote code execution in October CMSEcosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
october: GSA_kwCzR0hTQS01aGZqLXI3MjUtd3BjNM0jVg
october/system arbitrary code executionEcosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
october: GSA_kwCzR0hTQS13djIzLXBmajctMm1qas0jVw
October/System authenticated file write leads to remote code executionEcosystems: packagist
Packages: october/system
Source: github
Published: almost 3 years ago
High
Ecosystems: packagist
Packages: october/system, october/october
Source: github
Published: about 3 years ago
october: GSA_kwCzR0hTQS02Z2pmLTd3OTktajd4N80WOA
Deleted Admin Can Sign In to Admin InterfaceEcosystems: packagist
Packages: october/system, october/october
Source: github
Published: about 3 years ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: over 3 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg3NnItdmdmMy1qNnc1
October CMS auth bypass and account takeoverEcosystems: packagist
Packages: october/system
Source: github
Published: over 3 years ago
High
Ecosystems: packagist
Packages: october/system
Source: github
Published: over 3 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW14cjUtbWM5Ny02M3Jj
Account Takeover in OctobercmsEcosystems: packagist
Packages: october/system
Source: github
Published: over 3 years ago
Moderate
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 3 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZjcjgtNnE3ci1tNHdn
Bypass of fix for CVE-2020-26231, Twig sandbox escapeEcosystems: packagist
Packages: october/cms
Source: github
Published: over 3 years ago
Low
Ecosystems: packagist
Packages: october/backend
Source: github
Published: almost 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhoZngtaGdtZi12NnZw
Potential Host Header Poisoning on misconfigured serversEcosystems: packagist
Packages: october/backend
Source: github
Published: almost 4 years ago
Critical
Ecosystems: packagist
Packages: october/rain
Source: github
Published: almost 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdnZ3ctaDhwcC1yOTVy
October CMS Session ID not invalidated after logoutEcosystems: packagist
Packages: october/rain
Source: github
Published: almost 4 years ago
Low
Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI4OXYtY2d2Ny0zamh4
Bypass of fix for CVE-2020-15247, Twig sandbox escapeEcosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
Moderate
Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk0dnAtcm1xdi01ODc1
Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
High
Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3anItNmZqNy1mYzZo
Local File Inclusion by unauthenticated usersEcosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
Low
Ecosystems: packagist
Packages: october/backend
Source: github
Published: about 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ4M3YtNTUzeC0zYzRx
Stored XSS by authenticated backend user with access to upload filesEcosystems: packagist
Packages: october/backend
Source: github
Published: about 4 years ago
Low
Ecosystems: packagist
Packages: october/backend
Source: github
Published: about 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmamMteHJtZi01dnZ3
Privilege escalation by backend users assigned to the default "Publisher" system roleEcosystems: packagist
Packages: october/backend
Source: github
Published: about 4 years ago
Moderate
Ecosystems: packagist
Packages: october/rain
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU1bW0tNTM5OS03cjYz
Reliance on Cookies without validation in OctoberCMSEcosystems: packagist
Packages: october/rain
Source: github
Published: over 4 years ago
Low
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc0cGotN3A2OC0zdmd2
Stored XSS in OctoberEcosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Low
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNwYzItZm03cC1xMnZn
Cross-site Scripting in OctoberEcosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Moderate
Ecosystems: packagist
Packages: october/system, october/october
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY3M3ctcjl4Zy03Y3I5
Use of insecure jQuery version in OctoberCMSEcosystems: packagist
Packages: october/system, october/october
Source: github
Published: over 4 years ago
Moderate
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRyaG0tbTJmcC1oeDdx
Potential CSV Injection vector in OctoberCMSEcosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Moderate
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdnNngteHg3OC00NDhj
Reflected XSS when importing CSV in OctoberCMSEcosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Low
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk3MjItcnI2OC1yZnBn
Upload whitelisted files to any directory in OctoberCMSEcosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
Moderate
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp2NnYtZnZ2eC00OTMy
Arbitrary File Deletion vulnerability in OctoberCMSEcosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
Moderate
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXIyM2YtYzJqNS1yeDJm
Local File read vulnerability in OctoberCMSEcosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago