CVE-2026-78741: XSS
Published Sep 8, 2026
·Updated
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
Affected Software
1 affected component
Silverpeas Silverpeas Core<=6.4.6
Event History
Sep 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which versions are known to be affected?
Silverpeas Core versions 6.4.6 and earlier are identified as vulnerable.
2
Which feature should be prioritized for review?
The affected functionality is the wysiwyg-CKEditor image upload feature.