October (CMS)

Last updated
October
Developer(s) Alexey Bobkov, Samuel Georges
Initial releaseMay 15, 2014;11 years ago (2014-05-15) [1]
Stable release
v3.7.6 [2] / 2024-12-05 [±]
Repository
Written in PHP
Operating system Cross-platform
Type Content management system
License Source-available commercial software; subscription license required for continued use
Website octobercms.com OOjs UI icon edit-ltr-progressive.svg

October is a self-hosted content management system (CMS) based on the PHP programming language and Laravel web application framework. It supports MariaDB, MySQL, PostgreSQL, SQLite and SQL Server for the database back end [3] and uses a flat file database for the front end structure. [4] The October CMS covers a range of capabilities such as users, permissions, themes, and plugins, and is seen as a simpler alternative to WordPress. [5] [6] [7]

Contents

The platform is intended to have a small learning curve and a template system easily manageable with version control systems. [7] As of November 2023, October is the second-most starred PHP CMS repository hosted on GitHub [8] and is 17th most popular on the internet in open source category according to the number built. [9]

On April 12, 2021, October CMS transitioned from using an MIT License to a proprietary software model [10] citing concerns over a lack of sustainability with the open-source model.

Features

October offers the following features, among others:

Ukraine cyberattacks

From the 13th to 14th of January 2022, a known vulnerability in October CMS was used to deface the Ministry of Education and Science, the Ministry of Foreign Affairs, the Cabinet of Ministers and other Ukrainian government websites as part of the 2022 Ukraine cyberattacks. [14] [15] The Ukrainian Ministry of Digital Transformation announced that there was no data leak. [16] The vulnerabilities were fixed nearly a year before the attack, [17] although not all sites were running the latest version. [18] [19] Ukrainian cybersecurity agencies said the attack involved exploitation of CVE-2021-32648, [20] a vulnerability in the October CMS, as well as the exploitation of the notorious Log4Shell flaw, and DDoS attacks. [21]

See also

References

  1. "Announcement: OctoberCMS Beta", by daftspunk, May 15, 2014. Retrieved on 18 May 2015.
  2. "Changelog - OctoberCMS". octobercms.com. Retrieved 2024-12-10.
  3. "Database: Getting Started - Laravel - The PHP Framework For Web Artisans". laravel.com. Retrieved 2024-01-04.
  4. "Laravel 4 File-Based CMS", by Christopher Pitt, February 2, 2014
  5. "A Detailed Comparison Between WordPress And October CMS "
  6. "WordPress CMS vs October CMS: The Ultimate Showdown"
  7. 1 2 "Alternative Content Management — Part 2", by Christos Chiotis, May 20, 2014.
  8. "GitHub search", sort:stars language:PHP stars:>1 CMS. Retrieved on 20 May 2015.
  9. "October CMS Usage Statistics"
  10. "October CMS Moves to Become a Paid Platform"
  11. "CMS Components", Retrieved on 16 May 2015.
  12. 1 2 "Introducing October – a Laravel-based CMS", by Nick Salloum, November 17, 2014
  13. "Introducing October CMS", by Chad Cantrell, December 30, 2014
  14. "Sources tell me ~15 sites in Ukraine - all using October content management system - have been defaced", by Kim Zetter
  15. "Massive Cyber Attack Knocks Down Ukrainian Government Websites"
  16. "Official statement of the Ministry of Digital Investigation of a link with a hacker attack on a number of sites"
  17. "Build software better, together". GitHub .
  18. "Ukrainian government websites attacked: How could it happen?"
  19. "Multiple Ukrainian government websites hacked and defaced"
  20. "CVE-2021-32648 Detail"
  21. "Ukraine Attacks Involved Exploitation of Log4j, October CMS Vulnerabilities"