Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Alkacon

First CVE: Dec 16, 2005Active for: 21 yearsTotal CVEs: 36
28.1
VTI Score
Low

Alkacon's vulnerability profile centers on OpenCMS, a widely deployed open-source content management system, along with its associated templates and extensions. The disclosures concentrate on web-application input-handling and output-encoding weaknesses, particularly cross-site scripting, path traversal, cross-site request forgery, and CSV-formula injection, which are characteristic of CMS platforms that process user-supplied content and generate dynamic pages. Vulnerabilities affecting this vendor have a pronounced tendency to acquire public exploit code, reflecting both the open nature of the CMS codebase and the accessibility of the attack surface to a broad audience. Defenders should maintain current patches for internet-facing OpenCMS instances and apply input-validation and output-encoding controls at the application layer; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Alkacon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 16, 2005
20 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-8811HIGH
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administr
Mar 20, 20188.839NOYES
CVE-2019-13235MEDIUM
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
Aug 27, 20196.129NOYES
CVE-2019-13234MEDIUM
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
Aug 27, 20196.129NOYES
CVE-2019-13236MEDIUM
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
Aug 27, 20196.128NOYES
CVE-2018-8815MEDIUM
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image.
Mar 20, 20184.628NOYES
CVE-2023-6380MEDIUM
Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send
Dec 13, 20236.127NOYES
CVE-2023-6379MEDIUM
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to s
Dec 13, 20236.127NOYES
CVE-2019-13237MEDIUM
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxm
Aug 27, 20194.327NOYES
CVE-2019-11819HIGH
Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name
May 8, 20197.825NONO
CVE-2008-1300MEDIUM
Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 an
Mar 12, 20084.325NOYES
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
89%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (2.8%)
Network20 (55.6%)
Unknown15 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (55.6%)
High1 (2.8%)
Unknown15 (41.7%)
User Interaction
None4 (11.1%)
Unknown15 (41.7%)
Required17 (47.2%)
Privileges Required
Low10 (27.8%)
High0 (0.0%)
None11 (30.6%)
Unknown15 (41.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.6% of CVEs· 96th percentile
ExploitDB
10 CVEs
27.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Alkacon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Alkacon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Alkacon's Products

View all 3 CNAs →

Top CWEs