CVE-2026-2736 | Alkacon OpenCms 18.0 URL /search/index.html q cross site scripting
A vulnerability was found in Alkacon OpenCms 18.0. It has been declared as problematic. This issue affects some unknown processing of the file /search/index.html of the component URL Handler. Such manipulation of the argument q leads to cross site scripting.
This vulnerability is documented as CVE-2026-2736. The attack can be executed remotely. There is not any exploit available.