CVE-2024-35475: Openkm

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

Affected products

  • Openkm Openkm: up to and including 6.3.12

Published 2024-05-22. Last modified 2026-06-17.