Medium severity5.4NVD Advisory· Published Jul 1, 2026· Updated Jul 2, 2026
CVE-2026-54720
CVE-2026-54720
Description
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed. This issue was fixed in version 6.2.2/
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
silverstripe/frameworkPackagist | < 6.2.2 | 6.2.2 |
Affected products
2- Range: <6.2.2
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-gvrw-qqp5-jgc5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-54720ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2026-54720.yamlghsaWEB
- github.com/silverstripe/silverstripe-framework/commit/1bcb02adfc365c6436dc26ab2f6dd32d97f3979bghsaWEB
- github.com/silverstripe/silverstripe-framework/pull/11993ghsaWEB
- github.com/silverstripe/silverstripe-framework/releases/tag/6.2.2ghsaWEB
- github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-gvrw-qqp5-jgc5nvdWEB
- www.silverstripe.org/download/security-releases/cve-2026-54720nvdWEB
News mentions
0No linked articles in our index yet.