CVE-2025-57244
- EPSS 0.04%
- Veröffentlicht 05.11.2025 00:00:00
- Zuletzt bearbeitet 07.11.2025 19:48:25
OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the Email field is vulnerable when the POST request is modified to include encoded scrip...
CVE-2024-35475
- EPSS 0.19%
- Veröffentlicht 22.05.2024 14:15:08
- Zuletzt bearbeitet 12.11.2025 19:41:10
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges...
CVE-2023-50072
- EPSS 3.7%
- Veröffentlicht 13.01.2024 01:15:38
- Zuletzt bearbeitet 03.06.2025 14:15:33
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a ...
CVE-2021-33950
- EPSS 0.27%
- Veröffentlicht 17.02.2023 18:15:11
- Zuletzt bearbeitet 18.03.2025 19:15:40
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
CVE-2022-47413
- EPSS 0.26%
- Veröffentlicht 07.02.2023 22:15:10
- Zuletzt bearbeitet 25.03.2025 15:15:17
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.
CVE-2022-47414
- EPSS 0.27%
- Veröffentlicht 07.02.2023 22:15:10
- Zuletzt bearbeitet 25.03.2025 15:15:17
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality.
CVE-2022-3969
- EPSS 0.08%
- Veröffentlicht 13.11.2022 08:15:15
- Zuletzt bearbeitet 21.11.2024 07:20:38
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function getFileExtension of the file src/main/java/com/openkm/util/FileUtils.java. The manipulation leads to insecure temporary file. Upgra...
CVE-2022-40317
- EPSS 2.77%
- Veröffentlicht 09.09.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:21:18
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
CVE-2022-2131
- EPSS 0.29%
- Veröffentlicht 25.07.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:22
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.
CVE-2021-3628
- EPSS 0.26%
- Veröffentlicht 30.08.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:01
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.