Unrated severityNVD Advisory· Published Feb 19, 2026· Updated Feb 20, 2026
Stored Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms
CVE-2026-2735
Description
Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.