October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000119.json"