Silverpeas

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 20
    Known Exploited: 0
    3
    Critical Level Threats
    5
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-53698

    Silverpeas Personal Space Path Traversal Vulnerability

    Last Modified: Jun 10, 2026
    Published: Jun 10, 2026

    CVE-2026-30139

    Reflected XSS in Silverpeas AdvancedSearch That Enables Arbitrary JavaScript Execution

    Last Modified: Apr 27, 2026
    Published: Apr 22, 2026

    CVE-2025-46047

    A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.

    Last Modified: Sep 04, 2025
    Published: Sep 02, 2025

    CVE-2025-45055

    Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

    Last Modified: Jun 25, 2025
    Published: Jun 09, 2025

    CVE-2024-56923

    Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.

    Last Modified: May 28, 2025
    Published: Jan 22, 2025
    Items Per Page