Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Framework MEDIUM 5.4
CVE-2025-30148

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could …

Fix: after 5.3.23
Fix from $1,600 2025-04-10
Framework MEDIUM 5.4
CVE-2024-53277

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intenti…

Fix: 5.3.8+
Fix from $1,600 2025-01-14
Framework MEDIUM 5.4
CVE-2024-32981

Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content i…

Fix: 5.2.16+
Fix from $1,600 2024-07-17
Graphql MEDIUM 5.3
CVE-2023-44401

The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `…

Fix: 4.3.7 / 5.1.3+
Fix from $1,600 2024-01-23
Graphql HIGH 7.5
CVE-2023-40180

silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execu…

Fix: 3.8.2 / 4.1.3+
Fix from $1,950 2023-10-16
Framework MEDIUM 6.1
CVE-2023-22729

Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an at…

Fix: 4.12.5+
Fix from $1,600 2023-04-26
Graphql HIGH 7.5
CVE-2023-28104

`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted gr…

Patch available
Fix from $1,950 2023-03-16
Subsites HIGH 7.5
CVE-2022-42949

Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.

Fix: after 2.6.0
Fix from $1,950 2022-12-21
Silverstripe MEDIUM 5.4
CVE-2022-37421

Silverstripe silverstripe/cms through 4.11.0 allows XSS.

Fix: 4.11.3+
Fix from $1,600 2022-11-23
Framework MEDIUM 5.4
CVE-2022-38147

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).

Fix: 1.11.1+
Fix from $1,600 2022-11-23
Framework MEDIUM 5.4
CVE-2022-37429

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a java…

Fix: 4.11.13+
Fix from $1,600 2022-11-23
Framework MEDIUM 5.4
CVE-2022-37430

Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).

Fix: 4.11.13+
Fix from $1,600 2022-11-23
Framework MEDIUM 5.4
CVE-2022-38145

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta descript…

Fix: 1.11.1+
Fix from $1,600 2022-11-23
Asset Admin MEDIUM 5.4
CVE-2022-38724

Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.

Fix: after 4.11.0
Fix from $1,600 2022-11-23
Framework MEDIUM 6.1
CVE-2022-38462

Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

Fix: 4.11.13+
Fix from $1,600 2022-11-22
Framework HIGH 8.8
CVE-2022-38148

Silverstripe silverstripe/framework through 4.11 allows SQL Injection.

Fix: after 4.11.0
Fix from $1,950 2022-11-21
Framework MEDIUM 5.4
CVE-2022-38146

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).

Fix: after 4.11.0
Fix from $1,600 2022-11-21
Silverstripe MEDIUM 5.4
CVE-2022-28803

In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).

Fix: 4.10.9+
Fix from $1,600 2022-06-29
Silverstripe MEDIUM 6.5
CVE-2021-41559

Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.

Fix: 4.10.9+
Fix from $1,600 2022-06-28
Silverstripe MEDIUM 6.5
CVE-2022-24444

Silverstripe silverstripe/framework through 4.10 allows Session Fixation.

Fix: after 2.4.0
Fix from $1,600 2022-06-28
Framework MEDIUM 5.4
CVE-2022-25238

Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authentic…

Fix: after 4.10.0
Fix from $1,600 2022-06-28
Silverstripe Omnipay MEDIUM 6.5
CVE-2022-29254

silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (those that use intermediary s…

Fix: 2.5.2 / 3.0.2+
Fix from $1,600 2022-06-09
Silverstripe MEDIUM 6.1
CVE-2021-36150

SilverStripe Framework through 4.8.1 allows XSS.

Fix: 1.8.1+
Fix from $1,600 2021-10-07
Silverstripe MEDIUM 6.5
CVE-2020-26136

In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

Fix: 4.6.0+
Fix from $1,600 2021-06-08
Silverstripe MEDIUM 5.3
CVE-2020-26138

In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.

Fix: 4.6.0+
Fix from $1,600 2021-06-08
Mimevalidator HIGH 8.8
CVE-2020-9309

Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML co…

Fix: 2.0.0 / 4.6.0+
Fix from $1,950 2020-07-15
Silverstripe HIGH 7.5
CVE-2020-6164

In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact t…

Fix: 4.4.7 / 4.5.4+
Fix from $1,950 2020-07-15
Silverstripe MEDIUM 5.4
CVE-2020-9311

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to…

Fix: 3.7.5+
Fix from $1,600 2020-07-15
Silverstripe MEDIUM 5.3
CVE-2020-6165

SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms.…

Fix: 3.2.4 / 3.3.0+
Fix from $1,600 2020-07-15
Silverstripe MEDIUM 5.9
CVE-2019-19326

Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to …

Fix: 3.7.5 / 4.4.7+
Fix from $1,600 2020-07-15