Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.25%—Silverpeas CoreAI8/9/20269/9/2026
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.
AplazadaMedia (6.1)0.25%—Silverpeas CoreAICkeditorAI8/9/20269/9/2026
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
AplazadaMedia (6.1)0.25%—Silverpeas CoreAI8/9/20269/9/2026
Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.
AplazadaMedia (6.5)0.48%—SilverpeasAI10/6/202617/6/2026
Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
AplazadaMedia (6.1)0.26%—Silverpeas CoreAI22/4/202617/6/2026
A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.
AnalizadaMedia (6.5)0.36%—Silverpeas2/9/202517/6/2026
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.
AnalizadaMedia (5.4)0.30%—Silverpeas9/6/202517/6/2026
Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate…
AnalizadaMedia (5.4)0.31%—Silverpeas22/1/202517/6/2026
Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to…
AnalizadaAlta (7.5)0.54%—Silverpeas3/1/202517/6/2026
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
ModificadaCrítica (9.8)1.4%—Silverpeas16/8/20245/7/2026
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
ModificadaMedia (6.5)1.2%—Silverpeas16/8/20245/7/2026
An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.
AnalizadaMedia (5.4)0.77%—Silverpeas9/7/202417/6/2026
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and…
AnalizadaCrítica (9.8)0.94%—Silverpeas3/6/202417/6/2026
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
AnalizadaMedia (5.4)0.37%—Silverpeas22/5/202417/6/2026
Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.
ModificadaMedia (4.3)0.52%—Silverpeas13/12/20239/7/2026
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
ModificadaAlta (8.8)0.38%—Silverpeas13/12/20239/7/2026
Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.
ModificadaMedia (5.4)0.41%—Silverpeas13/12/20239/7/2026
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
ModificadaMedia (5.4)0.48%—Silverpeas13/12/20239/7/2026
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
ModificadaAlta (7.5)0.77%—Silverpeas13/12/20239/7/2026
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
ModificadaAlta (8.8)0.40%—Silverpeas13/12/20239/7/2026
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
ModificadaMedia (4.9)0.63%—Silverpeas13/12/20239/7/2026
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
ModificadaAlta (8.1)0.72%—Silverpeas13/12/20239/7/2026
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and…
ModificadaCrítica (9.9)5.0%—Silverpeas9/4/201917/6/2026
Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call. This vulnerability enables regular users to write arbitrary files on the underlying system with…