Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-26336 3 Alfresco, Atlassian, Hyland 5 Community Share, Alfresco Enterprise Content Management, Alfresco Community and 2 more 2026-03-05 7.5 High
Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.
CVE-2020-12873 1 Atlassian 1 Alfresco Enterprise Content Management 2024-11-21 8.8 High
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.