Vulnerabilities > Silverstripe > Framework > 4.11.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-23 | CVE-2023-48714 | Incorrect Permission Assignment for Critical Resource vulnerability in Silverstripe Framework Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. | 4.3 |
2023-04-26 | CVE-2023-22729 | Unspecified vulnerability in Silverstripe Framework Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. | 6.1 |
2023-04-26 | CVE-2023-22728 | Unspecified vulnerability in Silverstripe Framework Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. | 4.3 |
2022-11-23 | CVE-2022-37429 | Cross-site Scripting vulnerability in Silverstripe Framework Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. | 5.4 |
2022-11-23 | CVE-2022-37430 | Cross-site Scripting vulnerability in Silverstripe Framework Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). | 5.4 |
2022-11-22 | CVE-2022-38462 | Cross-site Scripting vulnerability in Silverstripe Framework Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | 6.1 |