Showing 3 vulnerabilities on this page for org.silverpeas.core:silverpeas-core-war

Signals CISA KEV Ransomware Nuclei
Maven vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Silverpeas Core has a reflected cross-site scripting vulnerability

A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.

CWE-79Apr 22, 2026
CVSS6.1v3.1EPSS0.188%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross-site Scripting in silverpeas

Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.

CWE-79Dec 13, 2023
CVSS5.4v3.1EPSS0.477%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Broken access control in Silverpeas

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.

CWE-284CWE-863Dec 13, 2023
CVSS8.1v3.1EPSS0.721%PoCs8SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX