Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-2736 Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sendi… Opencms Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-2735 Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘… Opencms Mitigation only Fix from $1,6002026-02-19 MEDIUM 6.5 CVE-2024-42699 Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via … Opencms No fix yet Fix from $1,6002025-04-21 MEDIUM 5.4 CVE-2024-41446 A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pa… Opencms No fix yet Fix from $1,6002025-04-21 MEDIUM 5.4 CVE-2024-41447 A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pa… Opencms No fix yet Fix from $1,6002025-04-18 MEDIUM 6.4 CVE-2024-5521 Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user having the roles of… Opencms Mitigation only Fix from $1,6002024-05-30 MEDIUM 5.4 CVE-2024-5520 Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient pri… Opencms Mitigation only Fix from $1,6002024-05-30 MEDIUM 6.1 CVE-2023-6379 Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability cou… Opencms 16.0.0+ Fix from $1,6002023-12-13 MEDIUM 6.1 CVE-2023-6380 Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a… Opencms 16.0.0+ Fix from $1,6002023-12-13 MEDIUM 6.1 CVE-2023-37602 An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via … Opencms No fix yet Fix from $1,6002023-07-20 MEDIUM 5.4 CVE-2023-31544 A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafte… Opencms Patch available Fix from $1,6002023-05-16 MEDIUM 5.4 CVE-2021-25968 In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious sc… Opencms 11.0.2+ Fix from $1,6002021-10-19 MEDIUM 6.5 CVE-2021-3312 An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfil… Opencms No fix yet Fix from $1,6002021-10-08 MEDIUM 6.1 CVE-2019-13234 In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. Opencms Apollo Template Patch available Fix from $1,6002019-08-27 MEDIUM 6.1 CVE-2019-13235 In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. Opencms Apollo Template Patch available Fix from $1,6002019-08-27 MEDIUM 6.1 CVE-2019-13236 In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. Opencms Patch available Fix from $1,6002019-08-27 HIGH 7.8 CVE-2019-11819 Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/us… Opencms after 10.5.4 Fix from $1,9502019-05-08 MEDIUM 6.1 CVE-2019-11818 Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/… Opencms after 10.5.4 Fix from $1,6002019-05-08 HIGH 8.8 CVE-2018-8811 Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack … Opencms No fix yet Fix from $1,9502018-03-20 MEDIUM 6.5 CVE-2006-3935 system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote … Opencms Patch available Fix from $1,6002006-07-31 MEDIUM 6.8 CVE-2005-4475 Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified … Opencms Mitigation only Fix from $1,6002005-12-22