CVE-2022-2131: Openkm
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.
Affected products
- Openkm Openkm: up to and including 6.3.10
Published 2022-07-25. Last modified 2026-06-17.