October Rain Library
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-25133 october/rain is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.1.9 and 0.0.0 - 3.7.13. | 0.0.0 - 3.7.134.0.0 - 4.1.9 | Medium |
CVE-2026-25125 october/rain is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 4.0.0 - 4.1.9 and 0.0.0 - 3.7.13. | 0.0.0 - 3.7.134.0.0 - 4.1.9 | Medium |
CVE-2026-22692 october/rain is vulnerable to Improper Access Control in versions 4.0.0 - 4.1.4 and 0.0.0 - 3.7.12. | 0.0.0 - 3.7.124.0.0 - 4.1.4 | Medium |
CVE-2017-15284 october/rain is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.0.426. | 0.0.0 - 1.0.426 | Medium |
CVE-2021-3311 october/rain is vulnerable to Insufficient Session Expiration in versions 0.0.0 - 1.0.472 and 1.1.0 - 1.1.2. | 0.0.0 - 1.0.4721.1.0 - 1.1.2 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.21 | — | — |
league/csv Version ~9.1 | — | — |
symfony/yaml Version ^6.4|^7.0 | — | — |
doctrine/dbal Version ^2.13.3|^3.1.4 | — | — |
laravel/tinker Version ~2.0|~3.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant