Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-30148 Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could … Framework after 5.3.23 Fix from $1,6002025-04-10 MEDIUM 5.4 CVE-2024-53277 Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intenti… Framework 5.3.8+ Fix from $1,6002025-01-14 MEDIUM 5.4 CVE-2024-32981 Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content i… Framework 5.2.16+ Fix from $1,6002024-07-17 MEDIUM 5.3 CVE-2023-44401 The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `… Graphql 4.3.7 / 5.1.3+ Fix from $1,6002024-01-23 HIGH 7.5 CVE-2023-40180 silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execu… Graphql 3.8.2 / 4.1.3+ Fix from $1,9502023-10-16 MEDIUM 6.1 CVE-2023-22729 Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an at… Framework 4.12.5+ Fix from $1,6002023-04-26 HIGH 7.5 CVE-2023-28104 `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted gr… Graphql Patch available Fix from $1,9502023-03-16 HIGH 7.5 CVE-2022-42949 Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. Subsites after 2.6.0 Fix from $1,9502022-12-21 MEDIUM 5.4 CVE-2022-37421 Silverstripe silverstripe/cms through 4.11.0 allows XSS. Silverstripe 4.11.3+ Fix from $1,6002022-11-23 MEDIUM 5.4 CVE-2022-38147 Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). Framework 1.11.1+ Fix from $1,6002022-11-23 MEDIUM 5.4 CVE-2022-37429 Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a java… Framework 4.11.13+ Fix from $1,6002022-11-23 MEDIUM 5.4 CVE-2022-37430 Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). Framework 4.11.13+ Fix from $1,6002022-11-23 MEDIUM 5.4 CVE-2022-38145 Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta descript… Framework 1.11.1+ Fix from $1,6002022-11-23 MEDIUM 5.4 CVE-2022-38724 Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. Asset Admin after 4.11.0 Fix from $1,6002022-11-23 MEDIUM 6.1 CVE-2022-38462 Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. Framework 4.11.13+ Fix from $1,6002022-11-22 HIGH 8.8 CVE-2022-38148 Silverstripe silverstripe/framework through 4.11 allows SQL Injection. Framework after 4.11.0 Fix from $1,9502022-11-21 MEDIUM 5.4 CVE-2022-38146 Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). Framework after 4.11.0 Fix from $1,6002022-11-21 MEDIUM 5.4 CVE-2022-28803 In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR). Silverstripe 4.10.9+ Fix from $1,6002022-06-29 MEDIUM 6.5 CVE-2021-41559 Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document. Silverstripe 4.10.9+ Fix from $1,6002022-06-28 MEDIUM 6.5 CVE-2022-24444 Silverstripe silverstripe/framework through 4.10 allows Session Fixation. Silverstripe after 2.4.0 Fix from $1,6002022-06-28 MEDIUM 5.4 CVE-2022-25238 Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authentic… Framework after 4.10.0 Fix from $1,6002022-06-28 MEDIUM 6.5 CVE-2022-29254 silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (those that use intermediary s… Silverstripe Omnipay 2.5.2 / 3.0.2+ Fix from $1,6002022-06-09 MEDIUM 6.1 CVE-2021-36150 SilverStripe Framework through 4.8.1 allows XSS. Silverstripe 1.8.1+ Fix from $1,6002021-10-07 MEDIUM 6.5 CVE-2020-26136 In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. Silverstripe 4.6.0+ Fix from $1,6002021-06-08 MEDIUM 5.3 CVE-2020-26138 In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. Silverstripe 4.6.0+ Fix from $1,6002021-06-08 HIGH 8.8 CVE-2020-9309 Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML co… Mimevalidator 2.0.0 / 4.6.0+ Fix from $1,9502020-07-15 HIGH 7.5 CVE-2020-6164 In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact t… Silverstripe 4.4.7 / 4.5.4+ Fix from $1,9502020-07-15 MEDIUM 5.4 CVE-2020-9311 In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to… Silverstripe 3.7.5+ Fix from $1,6002020-07-15 MEDIUM 5.3 CVE-2020-6165 SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms.… Silverstripe 3.2.4 / 3.3.0+ Fix from $1,6002020-07-15 MEDIUM 5.9 CVE-2019-19326 Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to … Silverstripe 3.7.5 / 4.4.7+ Fix from $1,6002020-07-15