Openkm kayıtları
openkm üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %6,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-377 Insecure Temporary File1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-2131İstismar yok | OpenKM XXE Injectionopenkm · openkm · CWE-611 | Kritik9,8 | — | %0,9 | 25 Tem 2022 |
32İzleyin | CVE-2019-11445Kavram kanıtı | OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home dopenkm · openkm · CWE-434 | Yüksek7,2 | — | %14,2 | 22 Nis 2019 |
30İzleyin | CVE-2021-33950İstismar yok | An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.openkm · openkm · CWE-611 | Yüksek7,5 | — | %0,7 | 17 Şub 2023 |
28İzleyin | CVE-2012-2316Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows ropenkm · openkm · CWE-352 | Orta6,8 | — | %4,3 | 9 Eyl 2012 |
25İzleyin | CVE-2024-35475İstismar yok | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12.openkm · openkm · CWE-352 | Orta6,4 | — | %0,3 | 22 May 2024 |
22İzleyin | CVE-2022-3969İstismar yok | OpenKM FileUtils.java getFileExtension temp fileopenkm · openkm · CWE-377 | Orta5,5 | — | %0,5 | 13 Kas 2022 |
21İzleyin | CVE-2014-8957İstismar yok | Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML viopenkm · openkm · CWE-79 | Orta5,4 | — | %1,2 | 6 Eki 2017 |
21İzleyin | CVE-2022-40317Kavram kanıtı | OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.openkm · openkm · CWE-79 | Orta5,4 | — | %1,1 | 9 Eyl 2022 |
21İzleyin | CVE-2021-3628İstismar yok | OpenKM Document Management Community vulnerable to Cross Site Scriptingopenkm · openkm · CWE-79 | Orta5,4 | — | %0,9 | 30 Ağu 2021 |
21İzleyin | CVE-2023-50072Kavram kanıtı | A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an autheopenkm · openkm · CWE-79 | Orta5,4 | — | %0,6 | 12 Oca 2024 |
21İzleyin | CVE-2022-47413İstismar yok | Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.openkm · openkm · CWE-79 | Orta5,4 | — | %0,5 | 7 Şub 2023 |
21İzleyin | CVE-2022-47414İstismar yok | If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" openkm · openkm · CWE-79 | Orta5,4 | — | %0,5 | 7 Şub 2023 |
21İzleyin | CVE-2025-57244İstismar yok | OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface.openkm · openkm · CWE-79 | Orta5,4 | — | %0,2 | 5 Kas 2025 |
20İzleyin | CVE-2008-2226İstismar yok | Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vopenkm · openkm · CWE-264 | Orta5,0 | — | %1,2 | 14 May 2008 |
18İzleyin | CVE-2012-2315Kavram kanıtı | admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remoopenkm · openkm · CWE-264 | Orta4,0 | — | %6,2 | 9 Eyl 2012 |
15İzleyin | CVE-2014-9017İstismar yok | Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web scropenkm · openkm · CWE-79 | Düşük3,5 | — | %1,7 | 11 Mar 2015 |
- CVE-2022-213139İzleyin
OpenKM XXE Injection
KritikCVSS 9,8İstismar yokEPSS %1openkm · openkm25 Tem 2022
- CVE-2019-1144532İzleyin
OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home d
YüksekCVSS 7,2Kavram kanıtıEPSS %14openkm · openkm22 Nis 2019
- CVE-2021-3395030İzleyin
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
YüksekCVSS 7,5İstismar yokEPSS %1openkm · openkm17 Şub 2023
- CVE-2012-231628İzleyin
Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows r
OrtaCVSS 6,8Kavram kanıtıEPSS %4openkm · openkm9 Eyl 2012
- CVE-2024-3547525İzleyin
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12.
OrtaCVSS 6,4İstismar yokEPSS %0openkm · openkm22 May 2024
- CVE-2022-396922İzleyin
OpenKM FileUtils.java getFileExtension temp file
OrtaCVSS 5,5İstismar yokEPSS %1openkm · openkm13 Kas 2022
- CVE-2014-895721İzleyin
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML vi
OrtaCVSS 5,4İstismar yokEPSS %1openkm · openkm6 Eki 2017
- CVE-2022-4031721İzleyin
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
OrtaCVSS 5,4Kavram kanıtıEPSS %1openkm · openkm9 Eyl 2022
- CVE-2021-362821İzleyin
OpenKM Document Management Community vulnerable to Cross Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %1openkm · openkm30 Ağu 2021
- CVE-2023-5007221İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authe
OrtaCVSS 5,4Kavram kanıtıEPSS %1openkm · openkm12 Oca 2024
- CVE-2022-4741321İzleyin
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.
OrtaCVSS 5,4İstismar yokEPSS %1openkm · openkm7 Şub 2023
- CVE-2022-4741421İzleyin
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note"
OrtaCVSS 5,4İstismar yokEPSS %1openkm · openkm7 Şub 2023
- CVE-2025-5724421İzleyin
OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface.
OrtaCVSS 5,4İstismar yokEPSS %0openkm · openkm5 Kas 2025
- CVE-2008-222620İzleyin
Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified v
OrtaCVSS 5,0İstismar yokEPSS %1openkm · openkm14 May 2008
- CVE-2012-231518İzleyin
admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remo
OrtaCVSS 4,0Kavram kanıtıEPSS %6openkm · openkm9 Eyl 2012
- CVE-2014-901715İzleyin
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web scr
DüşükCVSS 3,5İstismar yokEPSS %2openkm · openkm11 Mar 2015