#VU125890 Stored cross-site scripting in October CMS - CVE-2026-24906
Published: April 14, 2026
October CMS
OctoberCMS
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the backend editor markup classes fields when rendering stored markup class values in RichEditor dropdown menus. A remote user can inject a malicious markup class value to execute arbitrary script in a victim's browser.
Exploitation requires authenticated backend access with editor settings permissions and is triggered when a user opens a RichEditor.