Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2025-30148
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could …
Framework
after 5.3.23
MEDIUM 5.4
CVE-2024-53277
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intenti…
Framework
5.3.8+
MEDIUM 5.4
CVE-2024-32981
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content i…
Framework
5.2.16+
MEDIUM 5.3
CVE-2023-44401
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `…
Graphql
4.3.7 / 5.1.3+
HIGH 7.5
CVE-2023-40180
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execu…
Graphql
3.8.2 / 4.1.3+
MEDIUM 6.1
CVE-2023-22729
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an at…
Framework
4.12.5+
HIGH 7.5
CVE-2023-28104
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted gr…
Graphql
Patch available
HIGH 7.5
CVE-2022-42949
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
Subsites
after 2.6.0
MEDIUM 5.4
CVE-2022-37421
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
Silverstripe
4.11.3+
MEDIUM 5.4
CVE-2022-38147
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
Framework
1.11.1+
MEDIUM 5.4
CVE-2022-37429
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a java…
Framework
4.11.13+
MEDIUM 5.4
CVE-2022-37430
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
Framework
4.11.13+
MEDIUM 5.4
CVE-2022-38145
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta descript…
Framework
1.11.1+
MEDIUM 5.4
CVE-2022-38724
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
Asset Admin
after 4.11.0
MEDIUM 6.1
CVE-2022-38462
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
Framework
4.11.13+
HIGH 8.8
CVE-2022-38148
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
Framework
after 4.11.0
MEDIUM 5.4
CVE-2022-38146
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
Framework
after 4.11.0
MEDIUM 5.4
CVE-2022-28803
In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).
Silverstripe
4.10.9+
MEDIUM 6.5
CVE-2021-41559
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
Silverstripe
4.10.9+
MEDIUM 6.5
CVE-2022-24444
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
Silverstripe
after 2.4.0
MEDIUM 5.4
CVE-2022-25238
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authentic…
Framework
after 4.10.0
MEDIUM 6.5
CVE-2022-29254
silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (those that use intermediary s…
Silverstripe Omnipay
2.5.2 / 3.0.2+
MEDIUM 6.1
CVE-2021-36150
SilverStripe Framework through 4.8.1 allows XSS.
Silverstripe
1.8.1+
MEDIUM 6.5
CVE-2020-26136
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
Silverstripe
4.6.0+
MEDIUM 5.3
CVE-2020-26138
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
Silverstripe
4.6.0+
HIGH 8.8
CVE-2020-9309
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML co…
Mimevalidator
2.0.0 / 4.6.0+
HIGH 7.5
CVE-2020-6164
In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact t…
Silverstripe
4.4.7 / 4.5.4+
MEDIUM 5.4
CVE-2020-9311
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to…
Silverstripe
3.7.5+
MEDIUM 5.3
CVE-2020-6165
SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms.…
Silverstripe
3.2.4 / 3.3.0+
MEDIUM 5.9
CVE-2019-19326
Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to …
Silverstripe
3.7.5 / 4.4.7+