Openkm is a document management and content repository platform whose vulnerability profile concentrates in its core product and recurs through application-layer input-handling and request-forgery weaknesses, including cross-site scripting, CSRF, XML external entity injection, and insecure temporary file handling. These classes are typical of web-facing Java enterprise applications where sanitization and request validation are critical; the vendor's disclosures have a notable tendency toward public exploit availability and a meaningful share reach serious severity. Current CVE counts, exploitation activity, and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openkm over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11445HIGH OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileU | Apr 22, 2019 | 7.2 | 40 | NO | YES |
CVE-2012-2316MEDIUM Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentica | Sep 9, 2012 | 6.8 | 32 | NO | YES |
CVE-2022-2131CRITICAL OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perf | Jul 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2012-2315MEDIUM admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign adminis | Sep 9, 2012 | 4.0 | 26 | NO | YES |
CVE-2021-33950HIGH An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function. | Feb 17, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-3969MEDIUM A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function getFileExtension of the file src/main/java/com/openkm/util/Fi | Nov 13, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-40317MEDIUM OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. | Sep 9, 2022 | 5.4 | 21 | NO | NO |
CVE-2025-57244MEDIUM OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the Email field is | Nov 5, 2025 | 5.4 | 20 | NO | NO |
CVE-2014-8957MEDIUM Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tasks parameter. | Oct 6, 2017 | 5.4 | 20 | NO | NO |
CVE-2024-35475MEDIUM A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which al | May 22, 2024 | 6.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openkm.
Media articles that mention a CVE ID that affects a product developed by Openkm — matched by CVE ID, not by vendor name.