Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilities have been fixed by the Alkacon team in version 19.0.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user. | |
| Title | Reflected Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms | |
| First Time appeared |
Alkacon
Alkacon opencms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:alkacon:opencms:18.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Alkacon
Alkacon opencms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-19T08:39:46.150Z
Reserved: 2026-02-19T08:18:54.936Z
Link: CVE-2026-2736
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses