Skip to content
Noroxi

Openkm records

16 published records for vendor openkm.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
6.3%
Median publish → KEV
No record has entered KEV

All records

16 records
  • CVE-2022-2131
    39Monitor

    OpenKM XXE Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    openkm · openkmJul 25, 2022

  • OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home d

    HighCVSS 7.2Proof of conceptEPSS 14%

    openkm · openkmApr 22, 2019

  • An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.

    HighCVSS 7.5No exploitEPSS 1%

    openkm · openkmFeb 17, 2023

  • CVE-2012-2316
    28Monitor

    Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows r

    MediumCVSS 6.8Proof of conceptEPSS 4%

    openkm · openkmSep 9, 2012

  • A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12.

    MediumCVSS 6.4No exploitEPSS 0%

    openkm · openkmMay 22, 2024

  • CVE-2022-3969
    22Monitor

    OpenKM FileUtils.java getFileExtension temp file

    MediumCVSS 5.5No exploitEPSS 1%

    openkm · openkmNov 13, 2022

  • CVE-2014-8957
    21Monitor

    Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML vi

    MediumCVSS 5.4No exploitEPSS 1%

    openkm · openkmOct 6, 2017

  • OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.

    MediumCVSS 5.4Proof of conceptEPSS 1%

    openkm · openkmSep 9, 2022

  • CVE-2021-3628
    21Monitor

    OpenKM Document Management Community vulnerable to Cross Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    openkm · openkmAug 30, 2021

  • A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authe

    MediumCVSS 5.4Proof of conceptEPSS 1%

    openkm · openkmJan 12, 2024

  • Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.

    MediumCVSS 5.4No exploitEPSS 1%

    openkm · openkmFeb 7, 2023

  • If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note"

    MediumCVSS 5.4No exploitEPSS 1%

    openkm · openkmFeb 7, 2023

  • OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface.

    MediumCVSS 5.4No exploitEPSS 0%

    openkm · openkmNov 5, 2025

  • CVE-2008-2226
    20Monitor

    Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified v

    MediumCVSS 5.0No exploitEPSS 1%

    openkm · openkmMay 14, 2008

  • CVE-2012-2315
    18Monitor

    admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remo

    MediumCVSS 4.0Proof of conceptEPSS 6%

    openkm · openkmSep 9, 2012

  • CVE-2014-9017
    15Monitor

    Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web scr

    LowCVSS 3.5No exploitEPSS 2%

    openkm · openkmMar 11, 2015