CVE-2025-46047
- EPSS 0.02%
- Veröffentlicht 02.09.2025 00:00:00
- Zuletzt bearbeitet 04.09.2025 17:46:45
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.
CVE-2025-45055
- EPSS 0.04%
- Veröffentlicht 09.06.2025 00:00:00
- Zuletzt bearbeitet 25.06.2025 20:24:56
Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaSc...
CVE-2024-56923
- EPSS 0.17%
- Veröffentlicht 22.01.2025 21:15:09
- Zuletzt bearbeitet 28.05.2025 20:41:45
Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious ...
CVE-2024-48814
- EPSS 0.07%
- Veröffentlicht 03.01.2025 15:15:10
- Zuletzt bearbeitet 28.05.2025 20:15:50
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
CVE-2024-42850
- EPSS 49.78%
- Veröffentlicht 16.08.2024 19:15:10
- Zuletzt bearbeitet 05.06.2025 14:04:02
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
CVE-2024-42849
- EPSS 11.35%
- Veröffentlicht 16.08.2024 19:15:10
- Zuletzt bearbeitet 05.06.2025 14:04:16
An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.
CVE-2024-39031
- EPSS 6.74%
- Veröffentlicht 09.07.2024 21:15:15
- Zuletzt bearbeitet 05.06.2025 14:03:30
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload...
CVE-2024-36042
- EPSS 0.2%
- Veröffentlicht 03.06.2024 06:15:09
- Zuletzt bearbeitet 29.05.2025 20:21:54
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
CVE-2024-29392
- EPSS 0.12%
- Veröffentlicht 22.05.2024 16:15:09
- Zuletzt bearbeitet 23.04.2025 01:53:40
Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.
CVE-2023-47327
- EPSS 0.09%
- Veröffentlicht 13.12.2023 14:15:44
- Zuletzt bearbeitet 21.11.2024 08:30:10
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.