Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2020-9280
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder inste…
Silverstripe
after 4.5.0
HIGH 8.8
CVE-2019-12437
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
Silverstripe
after 4.3.3
MEDIUM 6.1
CVE-2019-19325
SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow mali…
Silverstripe
4.4.5 / 4.5.2+
MEDIUM 5.3
CVE-2019-16409
In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their UR…
Silverstripe
after 3.7.4
MEDIUM 5.4
CVE-2019-14272
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
Silverstripe
after 4.0.0
MEDIUM 5.3
CVE-2019-14273
In SilverStripe assets 4.0, there is broken access control on files.
Silverstripe
after 4.0.0
CRITICAL 9.8
CVE-2019-12204
In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.
Silverstripe
after 4.3.3
MEDIUM 6.3
CVE-2019-12203
SilverStripe through 4.3.3 allows session fixation in the "change password" form.
Silverstripe
after 4.3.3
MEDIUM 6.1
CVE-2019-12205
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
Silverstripe
after 4.3.3
MEDIUM 5.3
CVE-2019-12245
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a f…
Silverstripe
after 4.3.3
CRITICAL 9.8
CVE-2019-12149
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/regi…
Registry
1.0.9 / 2.0.4+
CRITICAL 9.8
CVE-2019-5715
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected …
Silverstripe
3.6.7 / 3.7.3+
MEDIUM 5.5
CVE-2017-18049
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and …
Silverstripe
after 3.6.2
MEDIUM 5.3
CVE-2017-12849
Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumera…
Silverstripe
after 3.5.4
MEDIUM 6.1
CVE-2017-14498
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/ass…
Silverstripe
after 3.6.0
MEDIUM 6.1
CVE-2017-5197
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript ev…
Silverstripe
after 3.4.3
MEDIUM 6.1
CVE-2015-8606
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to in…
Silverstripe
after 3.1.15
MEDIUM 5.8
CVE-2015-5062
Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13 allows remote attackers to redirect users to arbitrary web sites and conduct phish…
Silverstripe
No fix yet
MEDIUM 5.0
CVE-2013-6789
security/MemberLoginForm.php in SilverStripe 3.0.3 supports credentials in a GET request, which allows remote or local attackers to obtain sensitive …
Silverstripe
Patch available
MEDIUM 5.8
CVE-2013-2653
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing…
Silverstripe
Patch available
HIGH 7.5
CVE-2011-4960
SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to ex…
Silverstripe
Patch available
MEDIUM 6.8
CVE-2010-4824
SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when …
Silverstripe
Patch available
MEDIUM 6.8
CVE-2011-4959
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database u…
Silverstripe
Patch available
MEDIUM 6.8
CVE-2011-4962
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted co…
Silverstripe
Patch available
MEDIUM 6.0
CVE-2011-4961
SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator …
Silverstripe
Patch available
MEDIUM 5.0
CVE-2010-5078
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allow…
Silverstripe
Mitigation only
MEDIUM 5.0
CVE-2010-5079
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin…
Silverstripe
Patch available
MEDIUM 6.8
CVE-2010-5080
The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a …
Silverstripe
Mitigation only
MEDIUM 6.8
CVE-2010-5088
Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack…
Silverstripe
Patch available
MEDIUM 6.0
CVE-2010-5091
The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS auth…
Silverstripe
Patch available