Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilities have been fixed by the Alkacon team in version 19.0.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter. | |
| Title | Stored Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms | |
| First Time appeared |
Alkacon
Alkacon opencms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:alkacon:opencms:18.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Alkacon
Alkacon opencms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-19T08:38:31.071Z
Reserved: 2026-02-19T08:18:53.756Z
Link: CVE-2026-2735
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses