Alkacon
Alkacon Opencms: vulnerabilidades y CVE
Alkacon Opencms tiene 36 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-42346 | Alta (7.5) | 0.23% | — | 8 may 2026 | Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. |
| CVE-2023-42345 | Media (6.1) | 0.15% | — | 8 may 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. |
| CVE-2023-42344 | Alta (7.3) | 2.2% | — | 8 may 2026 | Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. |
| CVE-2023-42343 | Media (6.1) | 0.59% | — | 8 may 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. |
| CVE-2026-2736 | Media (5.1) | 0.27% | — | 19 feb 2026 | Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in… |
| CVE-2026-2735 | Media (5.1) | 0.24% | — | 19 feb 2026 | Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the… |
| CVE-2024-42699 | Media (6.5) | 0.35% | — | 21 abr 2025 | Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field |
| CVE-2024-41446 | Media (5.4) | 0.26% | — | 21 abr 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify… |
| CVE-2024-41447 | Media (5.4) | 0.26% | — | 18 abr 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify… |
| CVE-2024-5521 | Media (6.4) | 0.26% | — | 30 may 2024 | Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user having the roles of gallery editor or VFS resource manager will have the permission to… |
| CVE-2024-5520 | Media (5.4) | 0.28% | — | 30 may 2024 | Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can… |
| CVE-2023-6380 | Media (6.1) | 1.6% | — | 13 dic 2023 | Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them… |
| CVE-2023-6379 | Media (6.1) | 1.8% | — | 13 dic 2023 | Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript… |
| CVE-2023-37602 | Media (6.1) | 0.61% | — | 20 jul 2023 | An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. |
| CVE-2023-31544 | Media (5.4) | 0.40% | — | 16 may 2023 | A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module. |
| CVE-2021-25968 | Media (5.4) | 0.51% | — | 19 oct 2021 | In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a… |
| CVE-2021-3312 | Media (6.5) | 1.3% | — | 8 oct 2021 | An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG… |
| CVE-2019-13236 | Media (6.1) | 3.1% | — | 27 ago 2019 | In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. |
| CVE-2019-11819 | Alta (7.8) | 1.0% | — | 8 may 2019 | Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name. |
| CVE-2019-11818 | Media (6.1) | 0.77% | — | 8 may 2019 | Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript… |
| CVE-2018-8815 | Media (4.6) | 1.3% | — | 20 mar 2018 | Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image. |
| CVE-2018-8811 | Alta (8.8) | 2.1% | — | 20 mar 2018 | Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administrative users for requests that perform… |
| CVE-2015-2351 | Media (4.3) | 1.9% | — | 19 mar 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to… |
| CVE-2013-4600 | Media (4.3) | 1.9% | — | 9 ago 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to… |
| CVE-2008-1753 | Media (4.3) | 1.1% | — | 11 abr 2008 | Cross-site scripting (XSS) vulnerability in system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the searchfilter parameter, a… |
| CVE-2008-1510 | Media (4.3) | 1.5% | — | 25 mar 2008 | Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2)… |
| CVE-2008-1301 | Media (4) | 2.3% | — | 12 mar 2008 | Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a… |
| CVE-2008-1300 | Media (4.3) | 1.5% | — | 12 mar 2008 | Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to… |
| CVE-2008-1045 | Media (4.3) | 1.5% | — | 27 feb 2008 | Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via… |
| CVE-2006-3933 | Baja (3.5) | 1.1% | — | 31 jul 2006 | Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.2.2 allows remote authenticated users to inject arbitrary web script or HTML via the message body. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.