Vendor CVEs
Silverstripe
All CVEs
94 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-12204 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2019 | In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access. | ||
| CVE-2019-12149 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2019 | SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands. | ||
| CVE-2019-5715 | Cri | 0.64 | 9.8 | 0.02 | Apr 11, 2019 | All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject. | ||
| CVE-2022-38148 | Hig | 0.57 | 8.8 | 0.01 | Nov 21, 2022 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | ||
| CVE-2020-9309 | Hig | 0.57 | 8.8 | 0.02 | Jul 15, 2020 | Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the… | ||
| CVE-2019-12437 | Hig | 0.50 | 8.8 | 0.01 | Feb 19, 2020 | In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations, | ||
| CVE-2023-40180 | Hig | 0.42 | 7.5 | 0.01 | Oct 16, 2023 | silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed… | ||
| CVE-2023-28104 | Hig | 0.42 | 7.5 | 0.01 | Mar 16, 2023 | `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly… | ||
| CVE-2022-42949 | Hig | 0.42 | 7.5 | 0.01 | Dec 21, 2022 | Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. | ||
| CVE-2022-24444 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10 allows Session Fixation. | ||
| CVE-2021-41559 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2022 | Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document. | ||
| CVE-2020-26136 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. | ||
| CVE-2020-6164 | Hig | 0.42 | 7.5 | 0.02 | Jul 15, 2020 | In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL… | ||
| CVE-2020-9280 | Hig | 0.42 | 7.5 | 0.02 | Apr 15, 2020 | In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.… | ||
| CVE-2019-12203 | Med | 0.41 | 6.3 | 0.00 | Sep 25, 2019 | SilverStripe through 4.3.3 allows session fixation in the "change password" form. | ||
| CVE-2022-38462 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2022 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | ||
| CVE-2021-36150 | Med | 0.40 | 6.1 | 0.01 | Oct 7, 2021 | SilverStripe Framework through 4.8.1 allows XSS. | ||
| CVE-2017-5197 | Med | 0.40 | 6.1 | 0.01 | Mar 6, 2017 | There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element. | ||
| CVE-2015-8606 | Med | 0.40 | 6.1 | 0.02 | Apr 13, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/field/Members/ite… | ||
| CVE-2017-18049 | Med | 0.36 | 5.5 | 0.01 | Jan 23, 2018 | In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the… | ||
| CVE-2022-38147 | Med | 0.35 | 5.4 | 0.01 | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). | ||
| CVE-2022-37421 | Med | 0.35 | 5.4 | 0.01 | Nov 23, 2022 | Silverstripe silverstripe/cms through 4.11.0 allows XSS. | ||
| CVE-2022-38145 | Med | 0.35 | 5.4 | 0.01 | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view. | ||
| CVE-2022-37430 | Med | 0.35 | 5.4 | 0.01 | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). | ||
| CVE-2022-37429 | Med | 0.35 | 5.4 | 0.00 | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. | ||
| CVE-2022-38724 | Med | 0.35 | 5.4 | 0.01 | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. | ||
| CVE-2022-38146 | Med | 0.35 | 5.4 | 0.01 | Nov 21, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). | ||
| CVE-2022-28803 | Med | 0.35 | 5.4 | 0.01 | Jun 29, 2022 | In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR). | ||
| CVE-2022-25238 | Med | 0.35 | 5.4 | 0.01 | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code. | ||
| CVE-2020-26138 | Med | 0.35 | 5.3 | 0.01 | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. | ||
| CVE-2020-9311 | Med | 0.35 | 5.4 | 0.01 | Jul 15, 2020 | In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs. | ||
| CVE-2019-16409 | Med | 0.35 | 5.3 | 0.01 | Sep 26, 2019 | In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users… | ||
| CVE-2019-14273 | Med | 0.35 | 5.3 | 0.01 | Sep 26, 2019 | In SilverStripe assets 4.0, there is broken access control on files. | ||
| CVE-2019-14272 | Med | 0.35 | 5.4 | 0.01 | Sep 26, 2019 | In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS. | ||
| CVE-2019-12245 | Med | 0.35 | 5.3 | 0.01 | Sep 25, 2019 | SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension. | ||
| CVE-2017-12849 | Med | 0.35 | 5.3 | 0.01 | Oct 12, 2017 | Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks. | ||
| CVE-2026-24749 | Med | 0.34 | 5.3 | 0.00 | Apr 16, 2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the… | ||
| CVE-2023-44401 | Med | 0.34 | 5.3 | 0.00 | Jan 23, 2024 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is… | ||
| CVE-2019-19325 | Med | 0.33 | 6.1 | 0.01 | Feb 17, 2020 | SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be inserted through non-scalar FormField attributes, which allows performing XSS (Cross-Site… | ||
| CVE-2019-12205 | Med | 0.33 | 6.1 | 0.01 | Sep 25, 2019 | SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS. | ||
| CVE-2017-14498 | Med | 0.33 | 6.1 | 0.01 | Sep 15, 2017 | SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue… | ||
| CVE-2024-47605 | Med | 0.31 | 5.4 | 0.01 | Jan 14, 2025 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode,… | ||
| CVE-2020-25817 | Med | 0.31 | 4.8 | 0.01 | Jun 8, 2021 | SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user… | ||
| CVE-2019-19326 | Med | 0.31 | 5.9 | 0.01 | Jul 15, 2020 | Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Original-Url and X-HTTP-Method-Override headers, responses with malicious HTTP… | ||
| CVE-2026-54717 | Med | 0.28 | 5.4 | 0.00 | Aug 6, 2026 | Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is… | ||
| CVE-2025-30148 | Med | 0.28 | 5.4 | 0.00 | Apr 10, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of… | ||
| CVE-2025-25197 | Med | 0.28 | 5.4 | 0.00 | Apr 10, 2025 | Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report.… | ||
| CVE-2024-53277 | Med | 0.28 | 5.4 | 0.00 | Jan 14, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the given message. Some form messages include content that the… | ||
| CVE-2024-32981 | Med | 0.28 | 5.4 | 0.00 | Jul 17, 2024 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload… | ||
| CVE-2023-48714 | Med | 0.28 | 4.3 | 0.00 | Jan 23, 2024 | Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the… |
- risk 0.64cvss 9.8epss 0.01
In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.02
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
- risk 0.57cvss 8.8epss 0.01
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
- risk 0.57cvss 8.8epss 0.02
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the…
- risk 0.50cvss 8.8epss 0.01
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
- risk 0.42cvss 7.5epss 0.01
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed…
- risk 0.42cvss 7.5epss 0.01
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly…
- risk 0.42cvss 7.5epss 0.01
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
- risk 0.42cvss 6.5epss 0.01
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
- risk 0.42cvss 6.5epss 0.01
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
- risk 0.42cvss 6.5epss 0.01
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
- risk 0.42cvss 7.5epss 0.02
In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL…
- risk 0.42cvss 7.5epss 0.02
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.…
- risk 0.41cvss 6.3epss 0.00
SilverStripe through 4.3.3 allows session fixation in the "change password" form.
- risk 0.40cvss 6.1epss 0.00
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
- risk 0.40cvss 6.1epss 0.01
SilverStripe Framework through 4.8.1 allows XSS.
- risk 0.40cvss 6.1epss 0.01
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/field/Members/ite…
- risk 0.36cvss 5.5epss 0.01
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the…
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
- risk 0.35cvss 5.4epss 0.00
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
- risk 0.35cvss 5.4epss 0.01
In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).
- risk 0.35cvss 5.4epss 0.01
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
- risk 0.35cvss 5.3epss 0.01
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
- risk 0.35cvss 5.4epss 0.01
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
- risk 0.35cvss 5.3epss 0.01
In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users…
- risk 0.35cvss 5.3epss 0.01
In SilverStripe assets 4.0, there is broken access control on files.
- risk 0.35cvss 5.4epss 0.01
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
- risk 0.35cvss 5.3epss 0.01
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.
- risk 0.35cvss 5.3epss 0.01
Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.
- risk 0.34cvss 5.3epss 0.00
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the…
- risk 0.34cvss 5.3epss 0.00
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is…
- risk 0.33cvss 6.1epss 0.01
SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be inserted through non-scalar FormField attributes, which allows performing XSS (Cross-Site…
- risk 0.33cvss 6.1epss 0.01
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
- risk 0.33cvss 6.1epss 0.01
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue…
- risk 0.31cvss 5.4epss 0.01
silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode,…
- risk 0.31cvss 4.8epss 0.01
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user…
- risk 0.31cvss 5.9epss 0.01
Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Original-Url and X-HTTP-Method-Override headers, responses with malicious HTTP…
- risk 0.28cvss 5.4epss 0.00
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is…
- risk 0.28cvss 5.4epss 0.00
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of…
- risk 0.28cvss 5.4epss 0.00
Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report.…
- risk 0.28cvss 5.4epss 0.00
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the given message. Some form messages include content that the…
- risk 0.28cvss 5.4epss 0.00
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload…
- risk 0.28cvss 4.3epss 0.00
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the…
Page 1 of 2