GHSA-79jw-2f46-wv22 · Severity: high · Ecosystem: composer — Authenticated remote code execution in October CMS
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to bypass `cms.safe_mode` / `cms.enableSafeMode` in order to execute arbitrary code. This issue only affects admin panels that rely on safe mode and restricted permissions. To exploit this vulnerability, an attacker must first have access to the backend area. The issue has been patched in Build 474 (v1.0.474) and v1.1.10. Users unable to upgrade should apply https://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe to your installation manually.
Conclusion & alert: CVE-2022-21705 is rated Moderate Risk (56.8/100): CVSS High severity, with high exploitation likelihood (EPSS 8.68%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 70.34% | 8.68% | -61.65% |
| 2 | 2026-05-16 | 76.57% | 70.34% | -6.23% |
| 3 | 2026-03-29 | — | 76.57% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
| 8.5 | 2.0 | HIGH |
|
6.8 | 10.0 | [email protected] |
GHSA-79jw-2f46-wv22 · Severity: high · Ecosystem: composer — Authenticated remote code execution in October CMS
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| octobercms | october | < 1.0.474 | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
| octobercms | october | >= 1.1.0, < 1.1.10 | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
| octobercms | october | >= 2.0.0, < 2.1.27 | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe | Patch Third Party Advisory |
| https://github.com/octobercms/october/security/advisories/GHSA-79jw-2f46-wv22 | Issue Tracking Patch Third Party Advisory |