Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Packagist/october/rain — 6 CVEs · VulnScope
pkg:Packagist/
october/rain
6 total CVEs
CRITICAL
1
MEDIUM
5
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2021-3311
October CMS Session ID not invalidated after logout
from 0, < 1.0.472
MEDIUM
6.1
CVE-2020-15128
Reliance on Cookies without validation in OctoberCMS
>= 1.0.319, < 1.0.468
MEDIUM
5.4
CVE-2017-15284
OctoberCMS Cross-Site Scripting
from 0, < 1.0.426
MEDIUM
4.9
October Rain has Environment Variable Exfiltration via INI Parser Interpolation
>= 4.0.0, < 4.1.10
MEDIUM
4.9
October Rain has a Twig Sandbox Bypass via Collection Methods
>= 4.0.0, < 4.1.5
MEDIUM
4.8
October Rain has Stored XSS via SVG Filter Bypass
>= 4.0.0, < 4.1.10
CVE-2026-25125
CVE-2026-22692
CVE-2026-25133