#VU125886 Cross-site scripting in October CMS - CVE-2025-61676
Published: April 14, 2026
October CMS
OctoberCMS
Description
The vulnerability allows a remote user to execute arbitrary script in backend pages.
The vulnerability exists due to cross-site scripting in the branding and appearance styles input when processing stylesheet input in backend configuration forms. A remote privileged user can inject malicious HTML/JavaScript into the stylesheet field to execute arbitrary script in backend pages.
User interaction is required for a victim to view an affected backend page.