CVE-2026-27937: October CMS October
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 and 4.1.16.
Affected products
- October CMS October: from 4.0.0, before 4.1.16 (fixed in 4.1.16); before 3.7.16 (fixed in 3.7.16)
Published 2026-04-21. Last modified 2026-06-17.