VYPR

Packagist (Composer) package

silverstripe/userforms

pkg:composer/silverstripe/userforms

Vulnerabilities (2)

  • CVE-2026-54721HigAug 27, 2026
    affected < 6.4.9fixed 6.4.9

    Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authentic

  • CVE-2020-9280HigApr 15, 2020
    affected >= 5.0.0, < 5.4.2fixed 5.4.2

    In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.