Silverstripe
Products
23- 75 CVEs
- 23 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
- 0 CVEs
- 0 CVEs
- 0 CVEs
Recent CVEs
98| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-12204 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2019 | In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access. | ||
| CVE-2019-12149 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2019 | SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands. | ||
| CVE-2019-5715 | Cri | 0.64 | 9.8 | 0.02 | Apr 11, 2019 | All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject. | ||
| CVE-2022-38148 | Hig | 0.57 | 8.8 | 0.01 | Nov 21, 2022 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | ||
| CVE-2020-9309 | Hig | 0.57 | 8.8 | 0.02 | Jul 15, 2020 | Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the… | ||
| CVE-2026-54721 | Hig | 0.50 | 8.8 | 0.01 | Aug 27, 2026 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An… | ||
| CVE-2019-12437 | Hig | 0.50 | 8.8 | 0.01 | Feb 19, 2020 | In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations, | ||
| CVE-2023-40180 | Hig | 0.42 | 7.5 | 0.01 | Oct 16, 2023 | silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed… | ||
| CVE-2023-28104 | Hig | 0.42 | 7.5 | 0.01 | Mar 16, 2023 | `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly… | ||
| CVE-2022-42949 | Hig | 0.42 | 7.5 | 0.01 | Dec 21, 2022 | Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. | ||
| CVE-2022-24444 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10 allows Session Fixation. | ||
| CVE-2021-41559 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2022 | Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document. | ||
| CVE-2020-26136 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. | ||
| CVE-2020-6164 | Hig | 0.42 | 7.5 | 0.02 | Jul 15, 2020 | In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL… | ||
| CVE-2020-9280 | Hig | 0.42 | 7.5 | 0.02 | Apr 15, 2020 | In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.… | ||
| CVE-2019-12203 | Med | 0.41 | 6.3 | 0.00 | Sep 25, 2019 | SilverStripe through 4.3.3 allows session fixation in the "change password" form. | ||
| CVE-2026-54718 | Hig | 0.40 | 7.2 | 0.01 | Aug 27, 2026 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in… | ||
| CVE-2022-38462 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2022 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | ||
| CVE-2021-36150 | Med | 0.40 | 6.1 | 0.01 | Oct 7, 2021 | SilverStripe Framework through 4.8.1 allows XSS. | ||
| CVE-2020-25102 | Med | 0.40 | 6.1 | 0.01 | Sep 3, 2020 | silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/Dat… |
- risk 0.64cvss 9.8epss 0.01
In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.02
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
- risk 0.57cvss 8.8epss 0.01
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
- risk 0.57cvss 8.8epss 0.02
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the…
- risk 0.50cvss 8.8epss 0.01
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An…
- risk 0.50cvss 8.8epss 0.01
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
- risk 0.42cvss 7.5epss 0.01
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed…
- risk 0.42cvss 7.5epss 0.01
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly…
- risk 0.42cvss 7.5epss 0.01
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
- risk 0.42cvss 6.5epss 0.01
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
- risk 0.42cvss 6.5epss 0.01
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
- risk 0.42cvss 6.5epss 0.01
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
- risk 0.42cvss 7.5epss 0.02
In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL…
- risk 0.42cvss 7.5epss 0.02
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.…
- risk 0.41cvss 6.3epss 0.00
SilverStripe through 4.3.3 allows session fixation in the "change password" form.
- risk 0.40cvss 7.2epss 0.01
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in…
- risk 0.40cvss 6.1epss 0.01
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
- risk 0.40cvss 6.1epss 0.01
SilverStripe Framework through 4.8.1 allows XSS.
- risk 0.40cvss 6.1epss 0.01
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/Dat…