Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2025-57244
OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts scr…
Openkm
No fix yet
MEDIUM 6.4
CVE-2024-35475
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in…
Openkm
after 6.3.12
MEDIUM 5.4
CVE-2023-50072
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated …
Openkm
No fix yet
HIGH 7.5
CVE-2021-33950
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
Openkm
Patch available
MEDIUM 5.4
CVE-2022-47413
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.
Openkm
No fix yet
MEDIUM 5.4
CVE-2022-47414
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functional…
Openkm
No fix yet
MEDIUM 5.5
CVE-2022-3969
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function getFileExtension of the file s…
Openkm
6.3.12+
MEDIUM 5.4
CVE-2022-40317
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
Openkm
Patch available
CRITICAL 9.8
CVE-2022-2131
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flag…
Openkm
after 6.3.10
MEDIUM 5.4
CVE-2021-3628
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulner…
Openkm
Patch available
HIGH 7.2
CVE-2019-11445EPSS 14%
OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory …
Openkm
6.3.7+
MEDIUM 5.4
CVE-2014-8957
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tas…
Openkm
after 6.4.18
MEDIUM 6.8
CVE-2012-2316
Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote att…
Openkm
No fix yet
MEDIUM 5.0
CVE-2008-2226
Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vectors. …
Openkm
after 1.2