VYPR
Vendor

Silverstripe

Products
23
CVEs
98
Across products
119
Status
Private

Products

23

Recent CVEs

98
View all 98 CVEs →
  • CVE-2019-12204CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.01

    In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.

  • CVE-2019-12149CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.

  • CVE-2019-5715CriApr 11, 2019
    risk 0.64cvss 9.8epss 0.02

    All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.

  • CVE-2022-38148HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Silverstripe silverstripe/framework through 4.11 allows SQL Injection.

  • CVE-2020-9309HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.02

    Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the…

  • CVE-2026-54721HigAug 27, 2026
    risk 0.50cvss 8.8epss 0.01

    Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An…

  • CVE-2019-12437HigFeb 19, 2020
    risk 0.50cvss 8.8epss 0.01

    In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

  • CVE-2023-40180HigOct 16, 2023
    risk 0.42cvss 7.5epss 0.01

    silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed…

  • CVE-2023-28104HigMar 16, 2023
    risk 0.42cvss 7.5epss 0.01

    `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly…

  • CVE-2022-42949HigDec 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.

  • CVE-2022-24444MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Silverstripe silverstripe/framework through 4.10 allows Session Fixation.

  • CVE-2021-41559MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.

  • CVE-2020-26136MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.01

    In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

  • CVE-2020-6164HigJul 15, 2020
    risk 0.42cvss 7.5epss 0.02

    In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL…

  • CVE-2020-9280HigApr 15, 2020
    risk 0.42cvss 7.5epss 0.02

    In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.…

  • CVE-2019-12203MedSep 25, 2019
    risk 0.41cvss 6.3epss 0.00

    SilverStripe through 4.3.3 allows session fixation in the "change password" form.

  • CVE-2026-54718HigAug 27, 2026
    risk 0.40cvss 7.2epss 0.01

    Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in…

  • CVE-2022-38462MedNov 22, 2022
    risk 0.40cvss 6.1epss 0.01

    Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

  • CVE-2021-36150MedOct 7, 2021
    risk 0.40cvss 6.1epss 0.01

    SilverStripe Framework through 4.8.1 allows XSS.

  • CVE-2020-25102MedSep 3, 2020
    risk 0.40cvss 6.1epss 0.01

    silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/Dat…