Back

MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms

Published Feb 19, 2026

Description

Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.

Affected products

Remediation

Vendor solution

The vulnerabilities have been fixed by the Alkacon team in version 19.0.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Feb 19, 2026
Updated Mar 9, 2026
Reserved Feb 19, 2026
CISA Vulnrichment
Updated Feb 20, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a