OpenText™ Vulnerabilities and Affected Products
Vulnerabilities associated with Web Site Management Server.
Products
Clear product- Vertica5 vulnerabilities
- Operations Bridge Manager4 vulnerabilities
- Directory Services3 vulnerabilities
- Exceed Turbo X3 vulnerabilities
- Web Site Management Server3 vulnerabilities
- Asset Management X (AMX)2 vulnerabilities
- Filr2 vulnerabilities
- Network Node Manager i (NNMi)2 vulnerabilities
- Service Management Automation X (SMAX)2 vulnerabilities
- Service Manager2 vulnerabilities
- XM Fax2 vulnerabilities
- AccuRev1 vulnerability
- ALM Octane Management1 vulnerability
- ALM Octane.1 vulnerability
- Application Lifecycle Management (ALM),Quality Center1 vulnerability
- Carbonite Safe Server Backup1 vulnerability
- Content Management (Extended ECM)1 vulnerability
- CX-E Voice1 vulnerability
- Digital Asset Management.1 vulnerability
- Documentum™ Server1 vulnerability
- GroupWise1 vulnerability
- Hybrid Cloud Management X (HCMX)1 vulnerability
- Operations Agent1 vulnerability
- Operations Bridge Suite (Containerized)1 vulnerability
- Solutions Business Manager (SBM)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-9208HIGH | Stored-XSS vulnerability discovered in OpenText WSM Management Server.Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data. This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1. CWE-79Feb 19, 2026 | CVSS7.5v4.0 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13671MEDIUM | Cross Site request forgery vulnerability discovered in OpenText WSM Management Server.Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously. This issue affects Web Site Management Server: 16.7.0, 16.7.1. CWE-352Feb 19, 2026 | CVSS5.9v4.0 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13672HIGH | Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side. This issue affects Web Site Management Server: 16.7.0, 16.7.1. CWE-79Feb 19, 2026 | CVSS7.0v4.0 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |