Maven package
org.opencms/opencms-core
pkg:maven/org.opencms/opencms-core
Vulnerabilities (31)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-42346 | Hig | 7.5 | < 16.0 | 16.0 | May 8, 2026 | Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. | |
| CVE-2023-42345 | Med | 6.1 | < 16.0 | 16.0 | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. | |
| CVE-2023-42344 | Hig | 7.3 | < 10.5.1 | 10.5.1 | May 8, 2026 | Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. | |
| CVE-2023-42343 | Med | 6.1 | < 16.0 | 16.0 | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. | |
| CVE-2024-42699 | — | <= 17.0 | — | Apr 21, 2025 | Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field | ||
| CVE-2024-41446 | — | <= 17.0 | — | Apr 21, 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function. | ||
| CVE-2024-41447 | — | <= 17.0 | — | Apr 18, 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function. | ||
| CVE-2024-5520 | — | >= 16.0, < 17.0 | 17.0 | May 30, 2024 | Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the | ||
| CVE-2023-6379 | — | >= 14.0.0, < 16.0.0 | 16.0.0 | Dec 13, 2023 | Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing | ||
| CVE-2023-37602 | — | <= 15.0 | — | Jul 20, 2023 | An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. | ||
| CVE-2023-31544 | — | < 11.0.1 | 11.0.1 | May 16, 2023 | A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module. | ||
| CVE-2021-3312 | — | >= 11.0.0, < 12.0.0 | 12.0.0 | Oct 8, 2021 | An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document. | ||
| CVE-2019-13237 | — | < 11.0.1 | 11.0.1 | Aug 27, 2019 | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/se | ||
| CVE-2019-13236 | — | < 11.0.1 | 11.0.1 | Aug 27, 2019 | In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. | ||
| CVE-2019-13235 | — | < 11.0.1 | 11.0.1 | Aug 27, 2019 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | ||
| CVE-2019-13234 | — | < 11.0.1 | 11.0.1 | Aug 27, 2019 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | ||
| CVE-2019-11819 | — | < 11.0.0 | 11.0.0 | May 8, 2019 | Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name. | ||
| CVE-2019-11818 | — | < 11.0.0 | 11.0.0 | May 8, 2019 | Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be execut | ||
| CVE-2015-2351 | — | < 9.5.2 | 9.5.2 | Mar 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource par | ||
| CVE-2013-4600 | — | < 8.5.2 | 8.5.2 | Aug 9, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views/admin/admin-main.jsp or the (2) requestedResource parameter to system/login/inde |
- affected < 16.0fixed 16.0
Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.
- affected < 16.0fixed 16.0
A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
- affected < 10.5.1fixed 10.5.1
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
- affected < 16.0fixed 16.0
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
- CVE-2024-42699Apr 21, 2025affected <= 17.0
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field
- CVE-2024-41446Apr 21, 2025affected <= 17.0
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.
- CVE-2024-41447Apr 18, 2025affected <= 17.0
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.
- CVE-2024-5520May 30, 2024affected >= 16.0, < 17.0fixed 17.0
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the
- CVE-2023-6379Dec 13, 2023affected >= 14.0.0, < 16.0.0fixed 16.0.0
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing
- CVE-2023-37602Jul 20, 2023affected <= 15.0
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
- CVE-2023-31544May 16, 2023affected < 11.0.1fixed 11.0.1
A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module.
- CVE-2021-3312Oct 8, 2021affected >= 11.0.0, < 12.0.0fixed 12.0.0
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
- CVE-2019-13237Aug 27, 2019affected < 11.0.1fixed 11.0.1
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/se
- CVE-2019-13236Aug 27, 2019affected < 11.0.1fixed 11.0.1
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
- CVE-2019-13235Aug 27, 2019affected < 11.0.1fixed 11.0.1
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
- CVE-2019-13234Aug 27, 2019affected < 11.0.1fixed 11.0.1
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
- CVE-2019-11819May 8, 2019affected < 11.0.0fixed 11.0.0
Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.
- CVE-2019-11818May 8, 2019affected < 11.0.0fixed 11.0.0
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be execut
- CVE-2015-2351Mar 19, 2015affected < 9.5.2fixed 9.5.2
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource par
- CVE-2013-4600Aug 9, 2013affected < 8.5.2fixed 8.5.2
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views/admin/admin-main.jsp or the (2) requestedResource parameter to system/login/inde
Page 1 of 2