Vulnerabilidades en Openkm
7 resultadosAnálisis Vexday
OpenKM apresenta baixo volume de vulnerabilidades (3 CVEs) com nenhuma sob exploração ativa conhecida, reduzindo o risco imediato. Porém, todas as três vulnerabilidades foram publicadas nos últimos 90 dias e concentram-se em path traversal (CWE-22), indicando exposição recente a falhas de validação de entrada que podem permitir acesso não autorizado a arquivos.
CVE-2021-3628MEDIUMOpenKM Document Management Community vulnerable to Cross Site ScriptingEPSS 0.9%CVE-2022-2131HIGHOpenKM XXE InjectionEPSS 0.8%CVE-2026-42785HIGHOpenKM 6.3.12 Remote Code Execution via Administrative ScriptingEPSS 0.7%CVE-2026-42425HIGHOpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQueryEPSS 0.6%CVE-2022-47413MEDIUM
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.
EPSS 0.5%CVE-2022-47414MEDIUM
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" EPSS 0.5%CVE-2026-41917MEDIUMOpenKM 6.3.12 Local File Inclusion via Admin ScriptingEPSS 0.4%