Description
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Assess Impact
AI Analysis

Impact

Silverpeas Core versions 6.4.6 and earlier are affected by a cross‑site scripting vulnerability that can be triggered through the Multimedia library application. The flaw permits arbitrary script injection via the multimedia functionality. Typical XSS impacts such as defacement or data theft could result, inferred from the nature of the flaw.

Affected Systems

Silverpeas Core up to and including version 6.4.6 is affected. No other vendor or product information is listed in the advisory.

Risk and Exploitability

The vulnerability is not listed in the CISA KEV catalog and the EPSS score is <1%, indicating a low but non‑zero exploitation probability. The CVSS score of 6.1 denotes moderate severity. The precise attack vector is not detailed in the advisory, so the risk profile will depend on how the multimedia library might be exposed; typical XSS requires some form of user supplied data. Consequently, the risk is moderate; organizations should monitor for attempts to inject scripts via the multimedia upload paths and apply mitigations as soon as a vendor patch is available.

Generated by OpenCVE AI on September 10, 2026 at 04:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Silverpeas Core to a version newer than 6.4.6 where the XSS issue is resolved.
  • Limit access to the Multimedia library application to trusted administrators only.
  • Deploy a web application firewall or input‑validation rules to block malicious scripts in multimedia uploads.

Generated by OpenCVE AI on September 10, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title XSS Vulnerability in Silverpeas Core Multimedia Library

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T15:21:53.082Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-78742

cve-icon Vulnrichment

Updated: 2026-09-09T15:21:45.501Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T21:18:42.010

Modified: 2026-09-09T16:17:06.803

Link: CVE-2026-78742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')