Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
The vulnerabilities have been fixed by the Alkacon team in version 19.0.
Workaround
No workaround given by the vendor.
Mon, 23 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:alkacon:opencms:18.0.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 20 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter. | |
| Title | Stored Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms | |
| First Time appeared |
Alkacon
Alkacon opencms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:alkacon:opencms:18.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Alkacon
Alkacon opencms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-20T16:05:26.014Z
Reserved: 2026-02-19T08:18:53.756Z
Link: CVE-2026-2735
Updated: 2026-02-20T16:05:19.631Z
Status : Analyzed
Published: 2026-02-19T09:16:28.480
Modified: 2026-02-23T19:16:05.077
Link: CVE-2026-2735
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:07:55Z