No analysis available yet.
Vendor Solution
The vulnerabilities have been fixed by the Alkacon team in version 19.0.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:alkacon:opencms:18.0.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Sat, 21 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user. | |
| Title | Reflected Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms | |
| First Time appeared |
Alkacon
Alkacon opencms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:alkacon:opencms:18.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Alkacon
Alkacon opencms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-09T08:54:49.983Z
Reserved: 2026-02-19T08:18:54.936Z
Link: CVE-2026-2736
Updated: 2026-02-20T16:06:12.948Z
Status : Analyzed
Published: 2026-02-19T09:16:28.657
Modified: 2026-02-23T19:15:32.627
Link: CVE-2026-2736
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:07:54Z