CVE-2023-6379: Alkacon Opencms
Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
Affected products
- Alkacon Opencms: from 14.0.0, before 16.0.0 (fixed in 16.0.0)
Published 2023-12-13. Last modified 2026-06-17.