CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101005

HIGHCVSS 7.3NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101005 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101005

HIGHCVSS 7.3NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]