#VU125888 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in October CMS - CVE-2026-25133
Published: April 14, 2026
October CMS
OctoberCMS
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of script-related html tags in the SVG sanitization logic when processing uploaded SVG files through the Media Manager. A remote user can upload a specially crafted SVG file to execute arbitrary script in a victim's browser.
User interaction is required because the uploaded SVG must be viewed or embedded in a page to trigger.