← Zurück zur CVE-Suche

CVE-2026-38429

OpenCMS

Beschreibung

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

CVSS 9.8EPSS 0.3%Risiko 1.01
Quelle öffnen
Veröffentlicht
2026-05-05 17:17:04
Betroffene Versionen
<=v20
Typ
Core software
Zuletzt geändert
2026-07-24 21:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H