Alkacon OpenCMS XSS via Mercury template
Moderate severity
GitHub Reviewed
Published
Dec 13, 2023
to the GitHub Advisory Database
•
Updated Jun 20, 2025
Package
Affected versions
>= 14.0.0, < 16.0.0
Patched versions
16.0.0
Description
Published by the National Vulnerability Database
Dec 13, 2023
Published to the GitHub Advisory Database
Dec 13, 2023
Reviewed
Jun 20, 2025
Last updated
Jun 20, 2025
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
References