📦 Silverpeas

by Silverpeas

🔍 What is Silverpeas?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42850

CRITICAL CVSS 9.8 Aug 16, 2024

This vulnerability in Silverpeas allows attackers to bypass password complexity requirements when changing passwords, potentially enabling weak password usage. It affects Silverpeas v6.4.2 and lower v...

CVE-2024-48814

HIGH CVSS 7.5 Jan 3, 2025

A SQL injection vulnerability in Silverpeas 6.4.1 allows remote attackers to execute arbitrary SQL commands via the ViewType parameter in the findbywhereclause function. This can lead to unauthorized ...

CVE-2023-47320

HIGH CVSS 8.1 Dec 13, 2023

Silverpeas Core 6.3.1 and earlier versions have an incorrect access control vulnerability that allows low-privileged users to execute administrator-only functions. Specifically, attackers can put the ...

CVE-2023-47322

HIGH CVSS 8.8 Dec 13, 2023

This CSRF vulnerability in Silverpeas Core allows attackers to escalate privileges by tricking authenticated administrators into visiting malicious URLs. When exploited, it can grant administrative ac...

CVE-2023-47326

HIGH CVSS 8.8 Dec 13, 2023

Silverpeas Core 6.3.1 has a CSRF vulnerability in its Domain SQL Create function that allows attackers to trick authenticated users into executing unauthorized SQL operations. This affects all Silverp...

CVE-2025-45055

MEDIUM CVSS 5.4 Jun 9, 2025

Silverpeas 6.4.2 contains a stored XSS vulnerability in the event management module where authenticated users can upload malicious SVG files. When administrators view these files, embedded JavaScript ...

CVE-2024-56923

MEDIUM CVSS 5.4 Jan 22, 2025

A stored cross-site scripting (XSS) vulnerability in Silverpeas Core allows remote attackers to inject malicious JavaScript into the Name field of subscriptions. When an admin user views the affected ...

CVE-2024-42849

MEDIUM CVSS 6.5 Aug 16, 2024

A vulnerability in Silverpeas versions 6.4.2 and earlier allows remote attackers to cause denial of service through the password change function. This affects all Silverpeas deployments running vulner...

CVE-2024-39031

MEDIUM CVSS 5.4 Jul 9, 2024

This is a stored cross-site scripting (XSS) vulnerability in Silverpeas Core's calendar feature. An authenticated user can inject malicious scripts into event titles and descriptions, which execute au...