SILVERPEAS
[ RESEARCH ] - CVE-2026-78742 - Stored Cross Site Scripting (XSS) in introduction Multimedia library application (Silverpeas Core <=6.4.6)
·343 words·2 mins
RESEARCH
CVE-2026-78742
SILVERPEAS
Stored XSS in the Multimedia library introduction allows attackers to inject a JavaScript payload via the editor1 parameter, executing when users visit the application.
[ RESEARCH ] - CVE-2026-78741 - Stored XSS in wysiwyg-CKEditor image upload feature (Silverpeas <= 6.4.6)
·235 words·2 mins
RESEARCH
CVE-2026-78741
SILVERPEAS
Stored XSS in Silverpeas’ CKEditor image upload feature allows attackers to replace the filename with a JavaScript payload that executes after the file is uploaded.
[ RESEARCH ] - CVE-2026-78738 - Stored XSS Silverpeas Core 6.4.6 - File upload feature
·384 words·2 mins
RESEARCH
CVE-2026-78738
SILVERPEAS
Stored XSS in Silverpeas Document Management. By modifying the X-FULL-PATH header during file upload with an XSS payload, the payload executes when the file’s preview button is clicked.