Vulnerabilities
Vulnerable Software
Alkacon:  >> Opencms  >> 17.0.0  Security Vulnerabilities
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field
CVSS Score
6.5
EPSS Score
0.002
Published
2025-04-21
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-04-21
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-04-18
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.
CVSS Score
4.3
EPSS Score
0.003
Published
2010-03-26


Contact Us

Shodan ® - All rights reserved