Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.
History

Sat, 21 Feb 2026 07:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.
Title Reflected Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms
First Time appeared Alkacon
Alkacon opencms
Weaknesses CWE-79
CPEs cpe:2.3:a:alkacon:opencms:18.0:*:*:*:*:*:*:*
Vendors & Products Alkacon
Alkacon opencms
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2026-02-19T08:39:46.150Z

Updated: 2026-02-20T16:06:20.215Z

Reserved: 2026-02-19T08:18:54.936Z

Link: CVE-2026-2736

cve-icon Vulnrichment

Updated: 2026-02-20T16:06:12.948Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-02-19T09:16:28.657

Modified: 2026-02-19T15:52:39.260

Link: CVE-2026-2736

cve-icon Redhat

No data.