
CVE-2026-2736 Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a mal… https://www.cve.org/CVERecord?id=CVE-2026-2736
Post summary
The text discloses a reflected XSS vulnerability (CVE-2026-2736) in Alkacon's OpenCms v18.0, which permits attackers to execute arbitrary JavaScript through crafted URLs.

