VYPR
Vendor

Silverstripe

Products
22
CVEs
94
Across products
118
Status
Private

Products

22

Recent CVEs

94
View all 94 CVEs →
  • CVE-2019-12204CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.01

    In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.

  • CVE-2019-12149CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.

  • CVE-2019-5715CriApr 11, 2019
    risk 0.64cvss 9.8epss 0.02

    All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.

  • CVE-2022-38148HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Silverstripe silverstripe/framework through 4.11 allows SQL Injection.

  • CVE-2020-9309HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.02

    Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the…

  • CVE-2019-12437HigFeb 19, 2020
    risk 0.50cvss 8.8epss 0.01

    In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

  • CVE-2023-40180HigOct 16, 2023
    risk 0.42cvss 7.5epss 0.01

    silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed…

  • CVE-2023-28104HigMar 16, 2023
    risk 0.42cvss 7.5epss 0.01

    `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly…

  • CVE-2022-42949HigDec 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.

  • CVE-2022-24444MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Silverstripe silverstripe/framework through 4.10 allows Session Fixation.

  • CVE-2021-41559MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.

  • CVE-2020-26136MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.01

    In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

  • CVE-2020-6164HigJul 15, 2020
    risk 0.42cvss 7.5epss 0.02

    In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL…

  • CVE-2020-9280HigApr 15, 2020
    risk 0.42cvss 7.5epss 0.02

    In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.…

  • CVE-2019-12203MedSep 25, 2019
    risk 0.41cvss 6.3epss 0.00

    SilverStripe through 4.3.3 allows session fixation in the "change password" form.

  • CVE-2022-38462MedNov 22, 2022
    risk 0.40cvss 6.1epss 0.00

    Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

  • CVE-2021-36150MedOct 7, 2021
    risk 0.40cvss 6.1epss 0.01

    SilverStripe Framework through 4.8.1 allows XSS.

  • CVE-2017-5197MedMar 6, 2017
    risk 0.40cvss 6.1epss 0.01

    There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.

  • CVE-2015-8606MedApr 13, 2016
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/field/Members/ite…

  • CVE-2017-18049MedJan 23, 2018
    risk 0.36cvss 5.5epss 0.01

    In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the…