Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Silverpeas MEDIUM 6.5
CVE-2025-46047

A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin…

Patch available
Fix from $1,600 2025-09-02
Silverpeas MEDIUM 5.4
CVE-2025-45055

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malici…

Patch available
Fix from $1,600 2025-06-09
Silverpeas MEDIUM 5.4
CVE-2024-56923

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allo…

Fix: 6.4.2+
Fix from $1,600 2025-01-22
Silverpeas HIGH 7.5
CVE-2024-48814

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywher…

Patch available
Fix from $1,950 2025-01-03
Silverpeas CRITICAL 9.8
CVE-2024-42850

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

Fix: after 6.4.2
Fix from $2,300 2024-08-16
Silverpeas MEDIUM 6.5
CVE-2024-42849

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Fix: after 6.4.2
Fix from $1,600 2024-08-16
Silverpeas MEDIUM 5.4
CVE-2024-39031

In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from …

Fix: 6.4+
Fix from $1,600 2024-07-09
Silverpeas CRITICAL 9.8
CVE-2024-36042

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user…

Fix: 6.3.5+
Fix from $2,300 2024-06-03
Silverpeas MEDIUM 5.4
CVE-2024-29392

Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.

No fix yet
Fix from $1,600 2024-05-22
Silverpeas HIGH 8.8
CVE-2023-47322

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administr…

Fix: 6.3.2+
Fix from $1,950 2023-12-13
Silverpeas HIGH 8.8
CVE-2023-47326

Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.

Fix: 6.3.2+
Fix from $1,950 2023-12-13
Silverpeas HIGH 8.1
CVE-2023-47320

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…

Fix: 6.3.2+
Fix from $1,950 2023-12-13
Silverpeas HIGH 7.5
CVE-2023-47323

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all …

Fix: 6.3.2+
Fix from $1,950 2023-12-13
Silverpeas MEDIUM 5.4
CVE-2023-47324

Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.

Fix: 6.3.2+
Fix from $1,600 2023-12-13
Silverpeas MEDIUM 5.4
CVE-2023-47325

Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to t…

Fix: 6.3.2+
Fix from $1,600 2023-12-13
Silverpeas CRITICAL 9.9
CVE-2018-19586EPSS 5%

Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because cor…

Fix: after 6.0.2
Fix from $2,300 2019-04-09