Skip to main content

Vendor archive

silverstripe CVEs

Beta · best-effort

89 CVEs tagged to vendor silverstripe4 Critical, 11 High, 70 Medium, 4 Low, 0 Unrated.

CVE-2021-41559

Published Jun 28, 2022

Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29254

Published Jun 9, 2022

silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (those that use intermediary states like `isNotification()`…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-28661

Published Oct 7, 2021

Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26136

Published Jun 8, 2021

In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25817

Published Jun 8, 2021

SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9311

Published Jul 15, 2020

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through s…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6165

Published Jul 15, 2020

SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-chec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6164

Published Jul 15, 2020

In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19326

Published Jul 15, 2020

Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through m…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9280

Published Apr 15, 2020

In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12437

Published Feb 19, 2020

In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19325

Published Feb 17, 2020

SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12617

Published Sep 26, 2019

In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pollution.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-12245

Published Sep 25, 2019

SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12204

Published Sep 25, 2019

In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-50 of 89 CVEsPage 2 of 4