Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openkm

First CVE: May 14, 2008Active for: 18 yearsTotal CVEs: 16
31.1
VTI Score
Medium

Openkm is a document management and content repository platform whose vulnerability profile concentrates in its core product and recurs through application-layer input-handling and request-forgery weaknesses, including cross-site scripting, CSRF, XML external entity injection, and insecure temporary file handling. These classes are typical of web-facing Java enterprise applications where sanitization and request validation are critical; the vendor's disclosures have a notable tendency toward public exploit availability and a meaningful share reach serious severity. Current CVE counts, exploitation activity, and severity breakdowns are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openkm over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2008
18 years ago
Most Recent CVE
Nov 5, 2025
262 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11445HIGH
OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileU
Apr 22, 20197.240NOYES
CVE-2012-2316MEDIUM
Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentica
Sep 9, 20126.832NOYES
CVE-2022-2131CRITICAL
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perf
Jul 25, 20229.831NONO
CVE-2012-2315MEDIUM
admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign adminis
Sep 9, 20124.026NOYES
CVE-2021-33950HIGH
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
Feb 17, 20237.523NONO
CVE-2022-3969MEDIUM
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function getFileExtension of the file src/main/java/com/openkm/util/Fi
Nov 13, 20225.521NONO
CVE-2022-40317MEDIUM
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
Sep 9, 20225.421NONO
CVE-2025-57244MEDIUM
OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the Email field is
Nov 5, 20255.420NONO
CVE-2014-8957MEDIUM
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tasks parameter.
Oct 6, 20175.420NONO
CVE-2024-35475MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which al
May 22, 20246.419NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
75%
13%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network11 (68.8%)
Unknown4 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (68.8%)
High1 (6.3%)
Unknown4 (25.0%)
User Interaction
None4 (25.0%)
Unknown4 (25.0%)
Required8 (50.0%)
Privileges Required
Low8 (50.0%)
High2 (12.5%)
None2 (12.5%)
Unknown4 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
18.8% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openkm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openkm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openkm's Products

View all 5 CNAs →

Top CWEs