PT-2026-20773 · Alkacon · Alkacon Opencms

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2026-2736

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCms version 18.0
Description A Reflected Cross-site Scripting (XSS) issue exists in Alkacon's OpenCms version 18.0. This allows an attacker to execute JavaScript code in a user's browser. Exploitation occurs by sending a malicious URL containing the q parameter in the '/search/index.html' endpoint to a victim. Successful exploitation could lead to the theft of sensitive user information, such as session cookies, or allow an attacker to perform actions while impersonating the user.
Recommendations Apply a fix for Alkacon OpenCms version 18.0 to address the reflected XSS issue. As a temporary workaround, sanitize the q parameter in the '/search/index.html' endpoint to prevent the execution of malicious JavaScript code.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2736

Affected Products

Alkacon Opencms