Summary #
An overview of discovered Common Vulnerabilities and Exposures (CVE), through security research by HEKK.ONE, that are currently available for public disclosure.
2026 #
GITHUB: https://github.com/hekk-one/CVE
Bacularis #
[+] CVE-2026-95165 - Bacularis 5.4.0 - 6.5.1 is vulnerable to stored Cross Site Scripting (XSS) via the Organization name.
[+] CVE-2026-95166 - Bacularis 1.0.0 - 6.5.1 is vulnerable to stored Cross Site Scripting (XSS) via the Pool LabelFormat field.
[+] CVE-2026-88742 - Bacularis 1.0.0 - 6.5.0 is vulnerable to stored Cross Site Scripting (XSS) via the add client / client address field.
[+] CVE-2026-88743 - Bacularis 4.7.0 - 6.5.0 is vulnerable to stored Cross Site Scripting (XSS) via the director tags.
Silverpeas #
[+] CVE-2026-78738 - Silverpeas Core 6.4.6 is vulnerable to stored Cross Site Scripting (XSS) via the Document management file upload feature.
[+] CVE-2026-78741 - Silverpeas Core <=6.4.6 is vulnerable to stored Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
[+] CVE-2026-78742 - Silverpeas Core <=6.4.6 is vulnerable to stored Cross Site Scripting (XSS) via the Multimedia library application introduction.