Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-2735

Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.4%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-2735
  • Alkacon » Opencms » Version: 18.0.0
    cpe:2.3:a:alkacon:opencms:18.0.0


Contact Us

Shodan ® - All rights reserved