An overview of discovered Common Vulnerabilities and Exposures (CVE), through security research by HEKK.ONE, that are currently available for public disclosure.
[+] CVE-2026-78738 - Silverpeas Core 6.4.6 is vulnerable to stored Cross Site Scripting (XSS) via the Document management file upload feature. Details: https://hekk.one/posts/research/cve-2026-78738/
[+] CVE-2026-78741 - Silverpeas Core <=6.4.6 is vulnerable to stored Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. Details: https://hekk.one/posts/research/cve-2026-78741/
[+] CVE-2026-78742 - Silverpeas Core <=6.4.6 is vulnerable to stored Cross Site Scripting (XSS) via the Multimedia library application introduction. Details: https://hekk.one/posts/research/cve-2026-78742/