Alkacon's vulnerability profile centers on OpenCMS, a widely deployed open-source content management system, along with its associated templates and extensions. The disclosures concentrate on web-application input-handling and output-encoding weaknesses, particularly cross-site scripting, path traversal, cross-site request forgery, and CSV-formula injection, which are characteristic of CMS platforms that process user-supplied content and generate dynamic pages. Vulnerabilities affecting this vendor have a pronounced tendency to acquire public exploit code, reflecting both the open nature of the CMS codebase and the accessibility of the attack surface to a broad audience. Defenders should maintain current patches for internet-facing OpenCMS instances and apply input-validation and output-encoding controls at the application layer; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alkacon over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8811HIGH Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administr | Mar 20, 2018 | 8.8 | 39 | NO | YES |
CVE-2019-13235MEDIUM In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | Aug 27, 2019 | 6.1 | 29 | NO | YES |
CVE-2019-13234MEDIUM In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | Aug 27, 2019 | 6.1 | 29 | NO | YES |
CVE-2019-13236MEDIUM In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. | Aug 27, 2019 | 6.1 | 28 | NO | YES |
CVE-2018-8815MEDIUM Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image. | Mar 20, 2018 | 4.6 | 28 | NO | YES |
CVE-2023-6380MEDIUM Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send | Dec 13, 2023 | 6.1 | 27 | NO | YES |
CVE-2023-6379MEDIUM Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to s | Dec 13, 2023 | 6.1 | 27 | NO | YES |
CVE-2019-13237MEDIUM In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxm | Aug 27, 2019 | 4.3 | 27 | NO | YES |
CVE-2019-11819HIGH Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name | May 8, 2019 | 7.8 | 25 | NO | NO |
CVE-2008-1300MEDIUM Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 an | Mar 12, 2008 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alkacon.
Media articles that mention a CVE ID that affects a product developed by Alkacon — matched by CVE ID, not by vendor name.