Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pj6p-9p8x-5mfc | Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external host |
| Link | Providers |
|---|---|
| https://labs.watchtowr.com/xxe-you-can-depend-on-me-opencms/ |
|
Mon, 11 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XXE Vulnerability in Alkacon OpenCms Before Version 16 via External DOCTYPE |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alkacon
Alkacon opencms |
|
| Vendors & Products |
Alkacon
Alkacon opencms |
Fri, 08 May 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XXE Vulnerability in Alkacon OpenCms Before Version 16 via External DOCTYPE | |
| Weaknesses | CWE-611 |
Fri, 08 May 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-11T18:47:44.516Z
Reserved: 2023-09-08T00:00:00.000Z
Link: CVE-2023-42346
Updated: 2026-05-11T18:47:32.586Z
Status : Deferred
Published: 2026-05-08T05:16:09.850
Modified: 2026-05-11T20:20:58.467
Link: CVE-2023-42346
No data.
OpenCVE Enrichment
Updated: 2026-05-11T22:00:07Z
Github GHSA