github.com
https://github.com/Silverpeas/Silverpeas-Core CVE-2026-30139
MEDIUM
Silverpeas Core has a reflected cross-site scripting vulnerability
Record summary
CVE-2026-30139 has a selected CVSS score of 6.1 (medium).
Description
A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
org.silverpeas.core:silverpeas-core-warBrowse Maven / org.silverpeas.core:silverpeas-core-war | GitHub Advisory | Through 6.4-feature13197 | affected |
org.silverpeas.core:silverpeas-core-webBrowse Maven / org.silverpeas.core:silverpeas-core-web | GitHub Advisory | Through 6.4-feature13197 | affected |
References
5github.com
https://github.com/Silverpeas/Silverpeas-Core/commit/7b4bacc80d11ab60423bdc6eb69e0176e9c27fc7 github.com
https://github.com/Silverpeas/Silverpeas-Core/pull/1421 github.com
https://github.com/bodd1593/CVEs-huyle/tree/main/CVE-2026-30139 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-30139