Vulnerabilities > Silverstripe
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-23 | CVE-2023-44401 | Incorrect Authorization vulnerability in Silverstripe Graphql The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. | 5.3 |
2024-01-23 | CVE-2023-48714 | Incorrect Permission Assignment for Critical Resource vulnerability in Silverstripe Framework Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. | 4.3 |
2024-01-23 | CVE-2023-49783 | Incorrect Authorization vulnerability in Silverstripe Admin Silverstripe Admin provides a basic management interface for the Silverstripe Framework. | 4.3 |
2023-10-16 | CVE-2023-40180 | Resource Exhaustion vulnerability in Silverstripe Graphql silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. | 7.5 |
2023-04-26 | CVE-2023-22729 | Open Redirect vulnerability in Silverstripe Framework Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. | 6.1 |
2023-04-26 | CVE-2023-22728 | Missing Authorization vulnerability in Silverstripe Framework Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. | 4.3 |
2023-03-16 | CVE-2023-28104 | Allocation of Resources Without Limits or Throttling vulnerability in Silverstripe Graphql 4.1.1/4.2.2 `silverstripe/graphql` serves Silverstripe data as GraphQL representations. | 7.5 |
2022-11-23 | CVE-2022-37421 | Cross-site Scripting vulnerability in Silverstripe Silverstripe silverstripe/cms through 4.11.0 allows XSS. | 5.4 |
2022-11-23 | CVE-2022-38147 | Cross-site Scripting vulnerability in Silverstripe Framework Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). | 5.4 |
2022-11-23 | CVE-2022-37429 | Cross-site Scripting vulnerability in Silverstripe Framework Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. | 5.4 |