PT-2026-20772 · Alkacon · Alkacon Opencms

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2026-2735

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCms version 18.0
Description A stored Cross-Site Scripting (XSS) issue exists in Alkacon OpenCms version 18.0. The issue occurs because user-supplied data is not adequately validated when a POST request is sent to the following API endpoint: /blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt. The vulnerable parameter is text. This allows an attacker to inject malicious scripts that will be executed in the context of other users' browsers.
Recommendations Apply input validation to the text parameter when processing POST requests to the /blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2735

Affected Products

Alkacon Opencms