VYPR

Alfresco Share

by Hyland

CVEs (2)

  • CVE-2023-49964HigDec 11, 2023
    risk 0.60cvss 8.8epss 0.35

    An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions…

  • CVE-2026-26336HigFeb 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.