Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Unknown

CVE-2025-0708

Disclosure Date: January 24, 2025 (last updated January 25, 2025)
A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/model/addOrUpdate of the component Add Model Management Page. The manipulation of the argument 模板前缀 leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-5521

Disclosure Date: May 30, 2024 (last updated May 31, 2024)
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user having the roles of gallery editor or VFS resource manager will have the permission to upload images in the .svg format containing JavaScript code. The code will be executed the moment another user accesses the image.
0
Attacker Value
Unknown

CVE-2024-5520

Disclosure Date: May 30, 2024 (last updated May 31, 2024)
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field.
0
Attacker Value
Unknown

CVE-2023-6380

Disclosure Date: December 13, 2023 (last updated December 16, 2023)
Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.
Attacker Value
Unknown

CVE-2023-6379

Disclosure Date: December 13, 2023 (last updated December 16, 2023)
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
Attacker Value
Unknown

CVE-2023-37602

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
Attacker Value
Unknown

CVE-2023-31544

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module.
Attacker Value
Unknown

CVE-2021-25968

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2021-3312

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
Attacker Value
Unknown

CVE-2019-13234

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
0