OpenKM Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with OpenKM products.
Products
- OpenKM3 vulnerabilities
- OpenKM Community Edition3 vulnerabilities
- OpenKM Professional Edition3 vulnerabilities
- Document Management Community1 vulnerability
- OpenKM Document Management Community1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-42785HIGH | OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server. CWE-94May 26, 2026 | CVSS8.6v4.0 | EPSS0.679% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42425HIGH | OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQueryOpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/DatabaseQuery endpoint to extract sensitive data including usernames and password hashes from the OKM_USER table, modify permissions, or delete database records. CWE-89May 26, 2026 | CVSS8.6v4.0 | EPSS0.641% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41917MEDIUM | OpenKM 6.3.12 Local File Inclusion via Admin ScriptingOpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can exploit this to access sensitive files including /etc/passwd, configuration files containing database credentials, and JVM keystores accessible to the OpenKM process. CWE-22May 26, 2026 | CVSS6.9v4.0 | EPSS0.387% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35475MEDIUM | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands. CWE-352May 22, 2024 | CVSS6.4v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47414MEDIUM | If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality. CWE-79Feb 7, 2023 | CVSS5.4v3.1 | EPSS0.506% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47413MEDIUM | Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition. CWE-79Feb 7, 2023 | CVSS5.4v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2131HIGH | OpenKM XXE InjectionOpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack. CWE-611Jul 25, 2022 | CVSS8.5v3.1 | EPSS0.849% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-3628MEDIUM | OpenKM Document Management Community vulnerable to Cross Site ScriptingOpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter. CWE-79Aug 30, 2021 | CVSS4.6v3.1 | EPSS0.916% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |