Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opencms MEDIUM 6.1
CVE-2026-2736

Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sendi…

Mitigation only
Fix from $1,600 2026-02-19
Opencms MEDIUM 5.4
CVE-2026-2735

Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘…

Mitigation only
Fix from $1,600 2026-02-19
Opencms MEDIUM 6.5
CVE-2024-42699

Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via …

No fix yet
Fix from $1,600 2025-04-21
Opencms MEDIUM 5.4
CVE-2024-41446

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pa…

No fix yet
Fix from $1,600 2025-04-21
Opencms MEDIUM 5.4
CVE-2024-41447

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pa…

No fix yet
Fix from $1,600 2025-04-18
Opencms MEDIUM 6.4
CVE-2024-5521

Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user having the roles of…

Mitigation only
Fix from $1,600 2024-05-30
Opencms MEDIUM 5.4
CVE-2024-5520

Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient pri…

Mitigation only
Fix from $1,600 2024-05-30
Opencms MEDIUM 6.1
CVE-2023-6379

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability cou…

Fix: 16.0.0+
Fix from $1,600 2023-12-13
Opencms MEDIUM 6.1
CVE-2023-6380

Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a…

Fix: 16.0.0+
Fix from $1,600 2023-12-13
Opencms MEDIUM 6.1
CVE-2023-37602

An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via …

No fix yet
Fix from $1,600 2023-07-20
Opencms MEDIUM 5.4
CVE-2023-31544

A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafte…

Patch available
Fix from $1,600 2023-05-16
Opencms MEDIUM 5.4
CVE-2021-25968

In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious sc…

Fix: 11.0.2+
Fix from $1,600 2021-10-19
Opencms MEDIUM 6.5
CVE-2021-3312

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfil…

No fix yet
Fix from $1,600 2021-10-08
Opencms Apollo Template MEDIUM 6.1
CVE-2019-13234

In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.

Patch available
Fix from $1,600 2019-08-27
Opencms Apollo Template MEDIUM 6.1
CVE-2019-13235

In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.

Patch available
Fix from $1,600 2019-08-27
Opencms MEDIUM 6.1
CVE-2019-13236

In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.

Patch available
Fix from $1,600 2019-08-27
Opencms HIGH 7.8
CVE-2019-11819

Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/us…

Fix: after 10.5.4
Fix from $1,950 2019-05-08
Opencms MEDIUM 6.1
CVE-2019-11818

Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/…

Fix: after 10.5.4
Fix from $1,600 2019-05-08
Opencms HIGH 8.8
CVE-2018-8811

Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack …

No fix yet
Fix from $1,950 2018-03-20
Opencms MEDIUM 6.5
CVE-2006-3935

system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote …

Patch available
Fix from $1,600 2006-07-31
Opencms MEDIUM 6.8
CVE-2005-4475

Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified …

Mitigation only
Fix from $1,600 2005-12-22