Silverpeas
Silverpeas: vulnerabilidades y CVE
Silverpeas tiene 19 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses1
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-53698 | Media (6.5) | 0.48% | — | 10 jun 2026 | Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set. |
| CVE-2025-46047 | Media (6.5) | 0.36% | — | 2 sept 2025 | A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter. |
| CVE-2025-45055 | Media (5.4) | 0.30% | — | 9 jun 2025 | Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an… |
| CVE-2024-56923 | Media (5.4) | 0.31% | — | 22 ene 2025 | Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is… |
| CVE-2024-48814 | Alta (7.5) | 0.54% | — | 3 ene 2025 | SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function |
| CVE-2024-42850 | Crítica (9.8) | 1.4% | — | 16 ago 2024 | An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements. |
| CVE-2024-42849 | Media (6.5) | 1.2% | — | 16 ago 2024 | An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function. |
| CVE-2024-39031 | Media (5.4) | 0.77% | — | 9 jul 2024 | In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard… |
| CVE-2024-36042 | Crítica (9.8) | 0.94% | — | 3 jun 2024 | Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access. |
| CVE-2024-29392 | Media (5.4) | 0.37% | — | 22 may 2024 | Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController. |
| CVE-2023-47327 | Media (4.3) | 0.52% | — | 13 dic 2023 | The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the… |
| CVE-2023-47326 | Alta (8.8) | 0.38% | — | 13 dic 2023 | Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function. |
| CVE-2023-47325 | Media (5.4) | 0.41% | — | 13 dic 2023 | Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or… |
| CVE-2023-47324 | Media (5.4) | 0.48% | — | 13 dic 2023 | Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature. |
| CVE-2023-47323 | Alta (7.5) | 0.77% | — | 13 dic 2023 | The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to… |
| CVE-2023-47322 | Alta (8.8) | 0.40% | — | 13 dic 2023 | The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the… |
| CVE-2023-47321 | Media (4.9) | 0.63% | — | 13 dic 2023 | Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets. |
| CVE-2023-47320 | Alta (8.1) | 0.72% | — | 13 dic 2023 | Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access… |
| CVE-2018-19586 | Crítica (9.9) | 5.0% | — | 9 abr 2019 | Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call.… |