Vulnerability record · CVE-2021-32649 · published 14 January 2022
CVE-2021-32649: Octobercms october injection vulnerability
Octobercms · October
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP code by running specially crafted Twig code in the template markup. The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to upgrade may apply the patch to their installation manually as a workaround.
Description
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP code by running specially crafted Twig code in the template markup. The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to upgrade may apply the patch to their installation manually as a workaround.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/octobercms/october/commit/167b592eed291ae1563c8fcc5b9b34a03a300f26 | PatchThird Party Advisory |
| https://github.com/octobercms/october/security/advisories/GHSA-wv23-pfj7-2mjj | PatchThird Party Advisory |
| https://github.com/octobercms/october/commit/167b592eed291ae1563c8fcc5b9b34a03a300f26 | PatchThird Party Advisory |
| https://github.com/octobercms/october/security/advisories/GHSA-wv23-pfj7-2mjj | PatchThird Party Advisory |
Track CVE-2021-32649 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32649), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.