Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Silverpeas

First CVE: Apr 9, 2019Active for: 7 yearsTotal CVEs: 19
29.1
VTI Score
Low

Silverpeas is a niche, self-hosted enterprise content and knowledge management platform whose vulnerability profile concentrates in a single core product. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across web-layer and access-control weakness classes including cross-site scripting, cross-site request forgery, authentication bypass, and improper access control that are characteristic of complex web applications. Defenders deploying this platform should prioritize security updates and restrict administrative access; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Silverpeas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2019
7 years ago
Most Recent CVE
Jun 10, 2026
44 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-42850CRITICAL
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
Aug 16, 20249.832NONO
CVE-2018-19586CRITICAL
Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.
Apr 9, 20199.931NONO
CVE-2024-36042CRITICAL
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Jun 3, 20249.828NONO
CVE-2023-47326HIGH
Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.
Dec 13, 20238.828NONO
CVE-2023-47322HIGH
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL wh
Dec 13, 20238.827NONO
CVE-2023-47323HIGH
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other use
Dec 13, 20237.525NONO
CVE-2023-47320HIGH
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "M
Dec 13, 20238.125NONO
CVE-2026-53698MEDIUM
Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
Jun 10, 20266.524NONO
CVE-2025-46047MEDIUM
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login
Sep 2, 20256.522NONO
CVE-2024-48814HIGH
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
Jan 3, 20257.522NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
58%
26%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (63.2%)
Unknown0 (0.0%)
Required7 (36.8%)
Privileges Required
Low11 (57.9%)
High1 (5.3%)
None7 (36.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Silverpeas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Silverpeas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Silverpeas's Products

View all 1 CNAs →

Top CWEs