High severity8.8GHSA Advisory· Published Aug 27, 2026· Updated Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
CVE-2026-54721
Description
Impact
The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.
Reported by
Jack Wallace from Bastion Security
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: >= 7.1.0, < 7.1.1
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-g8wr-r2v2-vqc6ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yamlghsa
- github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702ghsa
- github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604cghsa
- github.com/silverstripe/silverstripe-userforms/pull/1441ghsa
- github.com/silverstripe/silverstripe-userforms/pull/1442ghsa
- github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9ghsa
- github.com/silverstripe/silverstripe-userforms/releases/tag/7.0.7ghsa
- github.com/silverstripe/silverstripe-userforms/releases/tag/7.1.1ghsa
- github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6ghsa
- www.silverstripe.org/download/security-releases/cve-2026-54721ghsa
News mentions
0No linked articles in our index yet.