Skip to main content

Vendor/product archive

silverstripe / framework CVEs

Beta · best-effort

15 CVEs tagged to silverstripe / framework0 Critical, 1 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2025-30148

Published Apr 10, 2025

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted en…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53277

Published Jan 14, 2025

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32981

Published Jul 17, 2024

Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a spe…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48714

Published Jan 23, 2024

Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to se…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22729

Published Apr 26, 2023

Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22728

Published Apr 26, 2023

Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38145

Published Nov 23, 2022

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37430

Published Nov 23, 2022

Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37429

Published Nov 23, 2022

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space ch…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38462

Published Nov 22, 2022

Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25238

Published Jun 28, 2022

Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1