VYPR
Moderate severityNVD Advisory· Published Aug 27, 2019· Updated Aug 4, 2024

CVE-2019-13234

CVE-2019-13234

Description

In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5 contain a stored XSS vulnerability in the search engine component.

CVE-2019-13234 describes a cross-site scripting (XSS) vulnerability in the Alkacon OpenCms Apollo Template versions 10.5.4 and 10.5.5. The flaw exists in the search engine functionality of the template, where insufficient sanitization of user-supplied input allows an attacker to inject arbitrary HTML or JavaScript code[1][2].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.opencms:opencms-coreMaven
< 11.0.111.0.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.