CVE-2024-24512: Pkp.sfu Open Journal Systems

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.

Affected products

  • Pkp.sfu Open Journal Systems: version 3.3 only

Published 2024-03-01. Last modified 2026-06-17.