Medium severity5.4NVD Advisory· Published Aug 6, 2026
CVE-2026-54717
CVE-2026-54717
Description
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
silverstripe/cmsPackagist | < 6.2.1 | 6.2.1 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-w3cp-g2pf-65whghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/cms/CVE-2026-54717.yamlghsaWEB
- github.com/silverstripe/silverstripe-cms/commit/62f9912baa18c80304f3fa8b6eca71bb5dc2d21envdWEB
- github.com/silverstripe/silverstripe-cms/pull/3175nvdWEB
- github.com/silverstripe/silverstripe-cms/releases/tag/6.2.1nvdWEB
- github.com/silverstripe/silverstripe-cms/security/advisories/GHSA-w3cp-g2pf-65whnvdWEB
- www.silverstripe.org/download/security-releases/cve-2026-54717ghsaWEB
News mentions
0No linked articles in our index yet.