Record summary

CVE-2026-30139 has a selected CVSS score of 6.1 (medium).

Description

A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

org.silverpeas.core:silverpeas-core-war

Browse Maven / org.silverpeas.core:silverpeas-core-war
GitHub AdvisoryThrough 6.4-feature13197affected

org.silverpeas.core:silverpeas-core-web

Browse Maven / org.silverpeas.core:silverpeas-core-web
GitHub AdvisoryThrough 6.4-feature13197affected

References

5