CVE-2025-61676 - CVE House
Back to Database
Status published Medium CVE-2025-61676

October CMS Vulnerable to Stored XSS via Branding Styles

Vulnerability Description

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-61676

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

october
Vulnerable Versions:
>= 4.0.0, < 4.0.12, < 3.7.13

Timeline

Official Publish: January 10th, 2026
Last Modified: January 12th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

Weaknesses (CWE)