CVE-2015-9549: Ocportal

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.

Affected products

Published 2020-08-03. Last modified 2026-06-17.