Products: 3
    Vulnerabilities: 19
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    12
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-42785

    OpenKM 6.3.12 Remote Code Execution via Administrative Scripting

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2026-42425

    OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2026-41917

    OpenKM 6.3.12 Local File Inclusion via Admin Scripting

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2025-57244

    OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the Email field is vulnerable when the POST request is modified to include encoded script tags, by passing frontend validation.

    Last Modified: Nov 07, 2025
    Published: Nov 05, 2025

    CVE-2024-35475

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

    Last Modified: Nov 12, 2025
    Published: May 22, 2024
    Items Per Page
    Openkm Vulnerabilities & Security CVEs | CVE-DB