Products: 3
    Vulnerabilities: 41
    Known Exploited: 0
    1
    Critical Level Threats
    4
    High Level Threats
    34
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-42346

    Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

    Last Modified: May 11, 2026
    Published: May 08, 2026

    CVE-2023-42344

    Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

    Last Modified: Jun 17, 2026
    Published: May 08, 2026

    CVE-2023-42345

    A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

    Last Modified: May 08, 2026
    Published: May 08, 2026

    CVE-2023-42343

    A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

    Last Modified: May 08, 2026
    Published: May 08, 2026

    CVE-2026-38429

    OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

    Last Modified: May 06, 2026
    Published: May 05, 2026
    Items Per Page
    Alkacon Vulnerabilities & Security CVEs | CVE-DB