Medium severity5.4NVD Advisory· Published Aug 16, 2024· Updated Jun 17, 2026
CVE-2024-25837
CVE-2024-25837
Description
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*range: <=1.3.8
- (no CPE)range: <=1.3.8
- October CMS/Bloghub Plugindescription
- Range: <1.3.9
Patches
Vulnerability mechanics
References
2- www.getastra.com/blog/vulnerability/stored-xss-vulnerability-in-bloghub-plugin/nvdThird Party Advisory
- github.com/RatMD/bloghub-plugin/blob/master/CHANGELOG.mdnvdRelease Notes
News mentions
0No linked articles in our index yet.