Openkm records
16 published records for vendor openkm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 6.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-377 Insecure Temporary File1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-2131No exploit | OpenKM XXE Injectionopenkm · openkm · CWE-611 | Critical9.8 | — | 0.9% | Jul 25, 2022 |
32Monitor | CVE-2019-11445Proof of concept | OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home dopenkm · openkm · CWE-434 | High7.2 | — | 14.2% | Apr 22, 2019 |
30Monitor | CVE-2021-33950No exploit | An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.openkm · openkm · CWE-611 | High7.5 | — | 0.7% | Feb 17, 2023 |
28Monitor | CVE-2012-2316Proof of concept | Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows ropenkm · openkm · CWE-352 | Medium6.8 | — | 4.3% | Sep 9, 2012 |
25Monitor | CVE-2024-35475No exploit | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12.openkm · openkm · CWE-352 | Medium6.4 | — | 0.3% | May 22, 2024 |
22Monitor | CVE-2022-3969No exploit | OpenKM FileUtils.java getFileExtension temp fileopenkm · openkm · CWE-377 | Medium5.5 | — | 0.5% | Nov 13, 2022 |
21Monitor | CVE-2014-8957No exploit | Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML viopenkm · openkm · CWE-79 | Medium5.4 | — | 1.2% | Oct 6, 2017 |
21Monitor | CVE-2022-40317Proof of concept | OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.openkm · openkm · CWE-79 | Medium5.4 | — | 1.1% | Sep 9, 2022 |
21Monitor | CVE-2021-3628No exploit | OpenKM Document Management Community vulnerable to Cross Site Scriptingopenkm · openkm · CWE-79 | Medium5.4 | — | 0.9% | Aug 30, 2021 |
21Monitor | CVE-2023-50072Proof of concept | A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an autheopenkm · openkm · CWE-79 | Medium5.4 | — | 0.6% | Jan 12, 2024 |
21Monitor | CVE-2022-47413No exploit | Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.openkm · openkm · CWE-79 | Medium5.4 | — | 0.5% | Feb 7, 2023 |
21Monitor | CVE-2022-47414No exploit | If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" openkm · openkm · CWE-79 | Medium5.4 | — | 0.5% | Feb 7, 2023 |
21Monitor | CVE-2025-57244No exploit | OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface.openkm · openkm · CWE-79 | Medium5.4 | — | 0.2% | Nov 5, 2025 |
20Monitor | CVE-2008-2226No exploit | Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vopenkm · openkm · CWE-264 | Medium5.0 | — | 1.2% | May 14, 2008 |
18Monitor | CVE-2012-2315Proof of concept | admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remoopenkm · openkm · CWE-264 | Medium4.0 | — | 6.2% | Sep 9, 2012 |
15Monitor | CVE-2014-9017No exploit | Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web scropenkm · openkm · CWE-79 | Low3.5 | — | 1.7% | Mar 11, 2015 |
- CVE-2022-213139Monitor
OpenKM XXE Injection
CriticalCVSS 9.8No exploitEPSS 1%openkm · openkmJul 25, 2022
- CVE-2019-1144532Monitor
OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home d
HighCVSS 7.2Proof of conceptEPSS 14%openkm · openkmApr 22, 2019
- CVE-2021-3395030Monitor
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
HighCVSS 7.5No exploitEPSS 1%openkm · openkmFeb 17, 2023
- CVE-2012-231628Monitor
Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows r
MediumCVSS 6.8Proof of conceptEPSS 4%openkm · openkmSep 9, 2012
- CVE-2024-3547525Monitor
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12.
MediumCVSS 6.4No exploitEPSS 0%openkm · openkmMay 22, 2024
- CVE-2022-396922Monitor
OpenKM FileUtils.java getFileExtension temp file
MediumCVSS 5.5No exploitEPSS 1%openkm · openkmNov 13, 2022
- CVE-2014-895721Monitor
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML vi
MediumCVSS 5.4No exploitEPSS 1%openkm · openkmOct 6, 2017
- CVE-2022-4031721Monitor
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
MediumCVSS 5.4Proof of conceptEPSS 1%openkm · openkmSep 9, 2022
- CVE-2021-362821Monitor
OpenKM Document Management Community vulnerable to Cross Site Scripting
MediumCVSS 5.4No exploitEPSS 1%openkm · openkmAug 30, 2021
- CVE-2023-5007221Monitor
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authe
MediumCVSS 5.4Proof of conceptEPSS 1%openkm · openkmJan 12, 2024
- CVE-2022-4741321Monitor
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.
MediumCVSS 5.4No exploitEPSS 1%openkm · openkmFeb 7, 2023
- CVE-2022-4741421Monitor
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note"
MediumCVSS 5.4No exploitEPSS 1%openkm · openkmFeb 7, 2023
- CVE-2025-5724421Monitor
OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface.
MediumCVSS 5.4No exploitEPSS 0%openkm · openkmNov 5, 2025
- CVE-2008-222620Monitor
Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified v
MediumCVSS 5.0No exploitEPSS 1%openkm · openkmMay 14, 2008
- CVE-2012-231518Monitor
admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remo
MediumCVSS 4.0Proof of conceptEPSS 6%openkm · openkmSep 9, 2012
- CVE-2014-901715Monitor
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web scr
LowCVSS 3.5No exploitEPSS 2%openkm · openkmMar 11, 2015