Vulnerabilities > Alkacon > Opencms > 11.0.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-19 | CVE-2021-25968 | Cross-site Scripting vulnerability in Alkacon Opencms In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. | 5.4 |
2021-10-08 | CVE-2021-3312 | XXE vulnerability in Alkacon Opencms 11.0/11.0.1/11.0.2 An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document. | 6.5 |