CVE-2023-6379: Alkacon Opencms

Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

Affected products

  • Alkacon Opencms: from 14.0.0, before 16.0.0 (fixed in 16.0.0)

Published 2023-12-13. Last modified 2026-06-17.