Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.25% | — | Silverpeas CoreAI | 8/9/2026 | 9/9/2026 | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. | |
| Aplazada | Media (6.1) | 0.25% | — | Silverpeas CoreAICkeditorAI | 8/9/2026 | 9/9/2026 | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. | |
| Aplazada | Media (6.1) | 0.25% | — | Silverpeas CoreAI | 8/9/2026 | 9/9/2026 | Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature. | |
| Aplazada | Media (6.5) | 0.48% | — | SilverpeasAI | 10/6/2026 | 17/6/2026 | Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set. | |
| Aplazada | Media (6.1) | 0.26% | — | Silverpeas CoreAI | 22/4/2026 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input. | |
| Analizada | Media (6.5) | 0.36% | — | Silverpeas | 2/9/2025 | 17/6/2026 | A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter. | |
| Analizada | Media (5.4) | 0.30% | — | Silverpeas | 9/6/2025 | 17/6/2026 | Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate… | |
| Analizada | Media (5.4) | 0.31% | — | Silverpeas | 22/1/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to… | |
| Analizada | Alta (7.5) | 0.54% | — | Silverpeas | 3/1/2025 | 17/6/2026 | SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function | |
| Modificada | Crítica (9.8) | 1.4% | — | Silverpeas | 16/8/2024 | 5/7/2026 | An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements. | |
| Modificada | Media (6.5) | 1.2% | — | Silverpeas | 16/8/2024 | 5/7/2026 | An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function. | |
| Analizada | Media (5.4) | 0.77% | — | Silverpeas | 9/7/2024 | 17/6/2026 | In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and… | |
| Analizada | Crítica (9.8) | 0.94% | — | Silverpeas | 3/6/2024 | 17/6/2026 | Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access. | |
| Analizada | Media (5.4) | 0.37% | — | Silverpeas | 22/5/2024 | 17/6/2026 | Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController. | |
| Modificada | Media (4.3) | 0.52% | — | Silverpeas | 13/12/2023 | 9/7/2026 | The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL. | |
| Modificada | Alta (8.8) | 0.38% | — | Silverpeas | 13/12/2023 | 9/7/2026 | Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function. | |
| Modificada | Media (5.4) | 0.41% | — | Silverpeas | 13/12/2023 | 9/7/2026 | Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces. | |
| Modificada | Media (5.4) | 0.48% | — | Silverpeas | 13/12/2023 | 9/7/2026 | Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature. | |
| Modificada | Alta (7.5) | 0.77% | — | Silverpeas | 13/12/2023 | 9/7/2026 | The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators. | |
| Modificada | Alta (8.8) | 0.40% | — | Silverpeas | 13/12/2023 | 9/7/2026 | The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application. | |
| Modificada | Media (4.9) | 0.63% | — | Silverpeas | 13/12/2023 | 9/7/2026 | Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets. | |
| Modificada | Alta (8.1) | 0.72% | — | Silverpeas | 13/12/2023 | 9/7/2026 | Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and… | |
| Modificada | Crítica (9.9) | 5.0% | — | Silverpeas | 9/4/2019 | 17/6/2026 | Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call. This vulnerability enables regular users to write arbitrary files on the underlying system with… |