Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-57244 OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts scr… Openkm No fix yet Fix from $1,6002025-11-05 MEDIUM 6.4 CVE-2024-35475 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in… Openkm after 6.3.12 Fix from $1,6002024-05-22 MEDIUM 5.4 CVE-2023-50072 A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated … Openkm No fix yet Fix from $1,6002024-01-13 HIGH 7.5 CVE-2021-33950 An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function. Openkm Patch available Fix from $1,9502023-02-17 MEDIUM 5.4 CVE-2022-47413 Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition. Openkm No fix yet Fix from $1,6002023-02-07 MEDIUM 5.4 CVE-2022-47414 If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functional… Openkm No fix yet Fix from $1,6002023-02-07 MEDIUM 5.5 CVE-2022-3969 A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function getFileExtension of the file s… Openkm 6.3.12+ Fix from $1,6002022-11-13 MEDIUM 5.4 CVE-2022-40317 OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. Openkm Patch available Fix from $1,6002022-09-09 CRITICAL 9.8 CVE-2022-2131 OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flag… Openkm after 6.3.10 Fix from $2,3002022-07-25 MEDIUM 5.4 CVE-2021-3628 OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulner… Openkm Patch available Fix from $1,6002021-08-30 HIGH 7.2 CVE-2019-11445EPSS 14% OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory … Openkm 6.3.7+ Fix from $1,9502019-04-22 MEDIUM 5.4 CVE-2014-8957 Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tas… Openkm after 6.4.18 Fix from $1,6002017-10-06 MEDIUM 6.8 CVE-2012-2316 Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote att… Openkm No fix yet Fix from $1,6002012-09-09 MEDIUM 5.0 CVE-2008-2226 Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vectors. … Openkm after 1.2 Fix from $1,6002008-05-14