← Voltar à pesquisa de CVEs

CVE-2026-38429

OpenCMS

Descrição

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

CVSS 9.8EPSS 0.3%Risco 1.01
Ver fonte
Publicação
2026-05-05 17:17:04
Versões afetadas
<=v20
Tipo
Core software
Última alteração
2026-07-24 21:10:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H