CVE-2019-11819: Alkacon Opencms

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.

Affected products

  • Alkacon Opencms: up to and including 10.5.4

Published 2019-05-08. Last modified 2026-06-17.