CVE-2025-61676: October CMS Vulnerable to Stored XSS via Branding Styles
A cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms:
- Branding and Appearances Styles A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Settings → Branding & Appearance → Styles.
A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users.
---
Impact - Persistent XSS across the backend interface. - Exploitable by lower-privileged accounts with the above permissions. - Potential consequences include privilege escalation, session hijacking, and execution of unauthorized actions in victim sessions.
---
Patches The vulnerability has been patched in v4.0.12 and v3.7.13. Stylesheet inputs are now sanitized to prevent injection of arbitrary HTML/JS.
All users are strongly encouraged to upgrade to the latest patched version.
---
Workarounds If upgrading immediately is not possible: - Restrict the permissions Customize Backend Styles to fully trusted administrators only.
This reduces exposure but does not fully eliminate risk.
---
Credits - Reported by Nakkouch Tarek
Other sources
October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61676?
CVE-2025-61676 is a moderate severity cross-site scripting (XSS) vulnerability affecting October CMS.
How do I fix CVE-2025-61676?
To fix CVE-2025-61676, update October CMS to version 4.0.12 or 3.7.13.
Who is affected by CVE-2025-61676?
CVE-2025-61676 affects users with the 'Customize Backend Styles' permission in October CMS.
What type of vulnerability is CVE-2025-61676?
CVE-2025-61676 is classified as a cross-site scripting (XSS) vulnerability.
What areas of October CMS are vulnerable due to CVE-2025-61676?
CVE-2025-61676 impacts the backend configuration forms, specifically the Branding and Appearance Styles settings.