Loading
Generated remediation guidance and an executive summary. No account required.
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.
Use CWE-79, Octobercms vendor hub and October product page to widen CVE-2024-25837 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-61676, CVE-2025-61674 and CVE-2026-24907 for nearby disclosures in the same product family.