CVE-2026-27937: October CMS: Reflected XSS via DataTable Form Widget
(updated )
A reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27937 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →