Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Silverstripe HIGH 7.5
CVE-2020-9280

In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder inste…

Fix: after 4.5.0
Fix from $1,950 2020-04-15
Silverstripe HIGH 8.8
CVE-2019-12437

In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

Fix: after 4.3.3
Fix from $1,950 2020-02-19
Silverstripe MEDIUM 6.1
CVE-2019-19325

SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow mali…

Fix: 4.4.5 / 4.5.2+
Fix from $1,600 2020-02-17
Silverstripe MEDIUM 5.3
CVE-2019-16409

In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their UR…

Fix: after 3.7.4
Fix from $1,600 2019-09-26
Silverstripe MEDIUM 5.4
CVE-2019-14272

In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.

Fix: after 4.0.0
Fix from $1,600 2019-09-26
Silverstripe MEDIUM 5.3
CVE-2019-14273

In SilverStripe assets 4.0, there is broken access control on files.

Fix: after 4.0.0
Fix from $1,600 2019-09-26
Silverstripe CRITICAL 9.8
CVE-2019-12204

In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.

Fix: after 4.3.3
Fix from $2,300 2019-09-25
Silverstripe MEDIUM 6.3
CVE-2019-12203

SilverStripe through 4.3.3 allows session fixation in the "change password" form.

Fix: after 4.3.3
Fix from $1,600 2019-09-25
Silverstripe MEDIUM 6.1
CVE-2019-12205

SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.

Fix: after 4.3.3
Fix from $1,600 2019-09-25
Silverstripe MEDIUM 5.3
CVE-2019-12245

SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a f…

Fix: after 4.3.3
Fix from $1,600 2019-09-25
Registry CRITICAL 9.8
CVE-2019-12149

SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/regi…

Fix: 1.0.9 / 2.0.4+
Fix from $2,300 2019-06-11
Silverstripe CRITICAL 9.8
CVE-2019-5715

All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected …

Fix: 3.6.7 / 3.7.3+
Fix from $2,300 2019-04-11
Silverstripe MEDIUM 5.5
CVE-2017-18049

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and …

Fix: after 3.6.2
Fix from $1,600 2018-01-23
Silverstripe MEDIUM 5.3
CVE-2017-12849

Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumera…

Fix: after 3.5.4
Fix from $1,600 2017-10-12
Silverstripe MEDIUM 6.1
CVE-2017-14498

SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/ass…

Fix: after 3.6.0
Fix from $1,600 2017-09-15
Silverstripe MEDIUM 6.1
CVE-2017-5197

There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript ev…

Fix: after 3.4.3
Fix from $1,600 2017-03-06
Silverstripe MEDIUM 6.1
CVE-2015-8606

Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to in…

Fix: after 3.1.15
Fix from $1,600 2016-04-13
Silverstripe MEDIUM 5.8
CVE-2015-5062

Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13 allows remote attackers to redirect users to arbitrary web sites and conduct phish…

No fix yet
Fix from $1,600 2015-06-24
Silverstripe MEDIUM 5.0
CVE-2013-6789

security/MemberLoginForm.php in SilverStripe 3.0.3 supports credentials in a GET request, which allows remote or local attackers to obtain sensitive …

Patch available
Fix from $1,600 2013-11-13
Silverstripe MEDIUM 5.8
CVE-2013-2653

security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing…

Patch available
Fix from $1,600 2013-11-13
Silverstripe HIGH 7.5
CVE-2011-4960

SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to ex…

Patch available
Fix from $1,950 2012-09-17
Silverstripe MEDIUM 6.8
CVE-2010-4824

SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when …

Patch available
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 6.8
CVE-2011-4959

SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database u…

Patch available
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 6.8
CVE-2011-4962

code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted co…

Patch available
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 6.0
CVE-2011-4961

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator …

Patch available
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 5.0
CVE-2010-5078

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allow…

Mitigation only
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 5.0
CVE-2010-5079

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin…

Patch available
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 6.8
CVE-2010-5080

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a …

Mitigation only
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 6.8
CVE-2010-5088

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack…

Patch available
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 6.0
CVE-2010-5091

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS auth…

Patch available
Fix from $1,600 2012-08-26