#VU125891 Stored cross-site scripting in October CMS - CVE-2026-24907
Published: April 14, 2026
October CMS
OctoberCMS
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in the viewer's browser context.
The vulnerability exists due to cross-site scripting in the Event Log mail preview feature when rendering logged mail messages. A remote user can create a malicious mail template content entry to execute arbitrary JavaScript in the viewer's browser context.
Exploitation requires authenticated backend access with mail template editing permissions, and user interaction is required when a superuser views the specific Event Log entry.