{"id":"GHSA-vmj7-7xmm-4349","summary":"Silverpeas Core has a reflected cross-site scripting vulnerability","details":"A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.","aliases":["CVE-2026-30139"],"modified":"2026-05-05T16:26:30.647838Z","published":"2026-04-22T18:31:44Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-30T17:47:45Z","nvd_published_at":"2026-04-22T16:16:53Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30139"},{"type":"WEB","url":"https://github.com/Silverpeas/Silverpeas-Core/pull/1421"},{"type":"WEB","url":"https://github.com/Silverpeas/Silverpeas-Core/commit/7b4bacc80d11ab60423bdc6eb69e0176e9c27fc7"},{"type":"PACKAGE","url":"https://github.com/Silverpeas/Silverpeas-Core"},{"type":"WEB","url":"https://github.com/bodd1593/CVEs-huyle/tree/main/CVE-2026-30139"}],"affected":[{"package":{"name":"org.silverpeas.core:silverpeas-core-war","ecosystem":"Maven","purl":"pkg:maven/org.silverpeas.core/silverpeas-core-war"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.4-feature13197"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vmj7-7xmm-4349/GHSA-vmj7-7xmm-4349.json"}},{"package":{"name":"org.silverpeas.core:silverpeas-core-web","ecosystem":"Maven","purl":"pkg:maven/org.silverpeas.core/silverpeas-core-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.4-feature13197"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vmj7-7xmm-4349/GHSA-vmj7-7xmm-4349.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}