CVE-2026-2735 | Alkacon OpenCms 18.0 POST Request org.opencms.ugc.CmsUgcEditService.gwt text cross site scripting
A vulnerability labeled as problematic has been found in Alkacon OpenCms 18.0. This affects an unknown function of the file /blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt of the component POST Request Handler. The manipulation of the argument text results in cross site scripting.
This vulnerability is known as CVE-2026-2735. It is possible to launch the attack remotely. No exploit is available.