Cross-site scripting in October CMS - #VU149490
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the backend origin.
The vulnerability exists due to improper neutralization of input during web page generation in the backend Event Log preview\'s client-side exception beautifier when an administrator opens a log preview containing crafted brace tokens in an exception message. A remote privileged user can supply a logged exception message containing crafted brace tokens to execute arbitrary script in the backend origin.
The crafted payload remains persistent until the affected log entry is deleted.