CVE-2026-2736

MEDIUM

OpenCms 18.0 - Reflected Cross-Site Scripting via Search Query Parameter

Title source: llm
STIX 2.1

Description

Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
alkacon/opencms 18.0.0
Published Feb 19, 2026
Tracked Since Feb 19, 2026