CVE-2026-101005
Published 28 September 2026 · tracked since 28 September 2026
Description
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-91206 MEDIUM 6.1
- CVE-2026-82382 MEDIUM 6.1
- CVE-2026-82383 HIGH 8.2
- CVE-2026-82384 CRITICAL 9.8
- CVE-2026-82385 MEDIUM 6.5
- CVE-2026-82386 HIGH 7.7
- CVE-2026-82387 MEDIUM 5.4
- CVE-2026-82546 MEDIUM 6.1
- CVE-2026-91204 MEDIUM 6.1
- CVE-2026-82375 HIGH 7.4