CVE-2021-32650
PHP vulnerability analysis and mitigation

Overview

October CMS, a self-hosted content management system based on the Laravel PHP Framework, contained a vulnerability (CVE-2021-32650) that allowed attackers with backend access to execute arbitrary PHP code through the theme import feature, bypassing the safe mode feature that prevents PHP execution in CMS templates. The vulnerability was discovered in versions 1.0.472 and 1.1.5, and was patched in versions 1.0.473 and 1.1.6 (GitHub Advisory).

Technical details

The vulnerability existed in the theme import functionality of October CMS. The issue allowed authenticated users to bypass the CMS safe mode feature, which is designed to prevent PHP code execution in CMS templates. The vulnerability was related to insufficient security checks in the theme import process, allowing malicious code to be executed despite safe mode being enabled (GitHub Commit).

Impact

An attacker with backend access could execute arbitrary PHP code on the server by exploiting the theme import feature. This bypass of the safe mode security feature could potentially lead to full server compromise, depending on the server configuration and permissions (GitHub Advisory).

Mitigation and workarounds

The issue was patched in October CMS versions 1.0.473 and 1.1.6. For users unable to upgrade, the fix can be applied manually by implementing the changes from commit 167b592. The patch adds additional security checks to prevent theme import operations when safe mode is enabled (GitHub Advisory, GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21857HIGH8.3
  • PHPPHP
  • redaxo/source
NoYesJan 07, 2026
CVE-2025-61676MEDIUM6.1
  • PHPPHP
  • october/system
NoYesJan 10, 2026
CVE-2025-61674MEDIUM6.1
  • PHPPHP
  • october/system
NoYesJan 10, 2026
CVE-2026-21896MEDIUM5.8
  • PHPPHP
  • getkirby/cms
NoYesJan 08, 2026
CVE-2026-22242MEDIUM4.9
  • PHPPHP
  • coreshop/core-shop
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management