Description
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

Silverpeas Core versions up to 6.4.6 contain a flaw in the CKEditor image upload component that allows a malicious actor to inject and execute arbitrary JavaScript. The vulnerability is manifested when an image is uploaded via the wysiwyg editor; the image data is not properly sanitized, enabling stored XSS payloads to run in any client that opens the edited content. Successful exploitation could let an attacker steal session cookies, deface web pages, or lift privilege within the user’s browser context.

Affected Systems

The flaw affects the Silverpeas Core product for all versions 6.4.6 and earlier. No specific build numbers or patch information is provided beyond the version cutoff. Users running a Silverpeas Core instance should examine their installed version to determine if it falls within the affected range.

Risk and Exploitability

The CVSS score is 6.1 and the EPSS value is < 1%, indicating a moderate exploitation probability. The vulnerability has not yet been catalogued in the CISA KEV list, indicating no publicly documented, widely used exploitation. Nevertheless, XSS flaws of this nature were historically leveraged by attackers to gain persistent footholds in web applications. Given the lack of a specialized vendor remediating patch in the snippet, the assessment leans toward a moderate to high risk for environments that allow unsanitized image uploads.

Generated by OpenCVE AI on September 10, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Silverpeas Core to a version newer than 6.4.6 if available from the vendor.
  • Disable or restrict the CKEditor image upload feature until a secure version is applied.
  • Deploy a Content Security Policy that blocks inline scripts and limits image sources to trusted domains.

Generated by OpenCVE AI on September 10, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via CKEditor Image Upload in Silverpeas Core <=6.4.6

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T13:04:36.533Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-78741

cve-icon Vulnrichment

Updated: 2026-09-09T13:04:24.026Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T21:18:41.903

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-78741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')