Silverpeas is a niche, self-hosted enterprise content and knowledge management platform whose vulnerability profile concentrates in a single core product. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across web-layer and access-control weakness classes including cross-site scripting, cross-site request forgery, authentication bypass, and improper access control that are characteristic of complex web applications. Defenders deploying this platform should prioritize security updates and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Silverpeas over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42850CRITICAL An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements. | Aug 16, 2024 | 9.8 | 32 | NO | NO |
CVE-2018-19586CRITICAL Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData. | Apr 9, 2019 | 9.9 | 31 | NO | NO |
CVE-2024-36042CRITICAL Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access. | Jun 3, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-47326HIGH Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function. | Dec 13, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-47322HIGH The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL wh | Dec 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-47323HIGH The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other use | Dec 13, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-47320HIGH Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "M | Dec 13, 2023 | 8.1 | 25 | NO | NO |
CVE-2026-53698MEDIUM Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set. | Jun 10, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-46047MEDIUM A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login | Sep 2, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-48814HIGH SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function | Jan 3, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Silverpeas.
Media articles that mention a CVE ID that affects a product developed by Silverpeas — matched by CVE ID, not by vendor name.