CMS
octobercms/october
Self-hosted CMS platform based on the Laravel PHP Framework.
#cms#framework#cmf#laravel#php#platform#octobercms#backend#cms-platform
スコア
75
/ 100
Star
11,138
Fork
2,209
Open Issue
11
サイズ
76MB
言語
PHP ★
最終push
7 日前
Docker
—
採点内訳
過去CVE 20件 (やや多い)
✓直近 push: 7 日前
✓得意言語 (PHP)
✓オープンissue 11件
—中規模 (76MB)
✓Docker 未対応
—10k–50k: 中級 (★11,138)
—※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (20 件)
- Editor Sub-Permission Bypass for Asset and Blueprint File Operations
- Reflected XSS via DataTable Form Widget
- Safe Mode Bypass via Twig Database Write Operations
- Safe Mode Bypass via CSS Preprocessor Compilers
- Stored XSS via SVG Filter Bypass
- Environment Variable Exfiltration via INI Parser Interpolation
- Stored XSS in Backend Editor Markup Classes
- Stored XSS in Event Log Mail Preview
- Twig Sandbox Bypass via Collection Methods
- Stored XSS via Branding Styles
- Stored XSS via Editor Settings
- Unprotected SVG Rename in Media Manager
- Reflected XSS via X-October-Request-Handler Header
- Open Redirect for Administrator Accounts
- Stored XSS by authenticated backend user with improper configuration
- Safe mode bypass using Page template injection
- Safe mode bypass using Twig sandbox escape
- Safe Mode bypass leads to authenticated Remote Code Execution
- RCE via race condition in upload process
- Compromised gateway causes data breach