Skip to main content

Vendor/product archive

silverstripe / graphql CVEs

Beta · best-effort

3 CVEs tagged to silverstripe / graphql0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-44401

Published Jan 23, 2024

The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40180

Published Oct 16, 2023

silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28104

Published Mar 16, 2023

`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denia…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1