Vulnerabilities > Silverstripe

DATE CVE VULNERABILITY TITLE RISK
2022-06-28 CVE-2022-25238 Cross-site Scripting vulnerability in Silverstripe Framework
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
network
low complexity
silverstripe CWE-79
5.4
2022-06-28 CVE-2022-29858 Improper Authentication vulnerability in Silverstripe Assets
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
network
low complexity
silverstripe CWE-287
4.3
2022-06-09 CVE-2022-29254 Unspecified vulnerability in Silverstripe Silverstripe-Omnipay
silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library.
network
low complexity
silverstripe
6.5
2021-10-07 CVE-2021-28661 Incorrect Authorization vulnerability in Silverstripe
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
network
low complexity
silverstripe CWE-863
4.3
2021-10-07 CVE-2021-36150 Cross-site Scripting vulnerability in Silverstripe
SilverStripe Framework through 4.8.1 allows XSS.
network
low complexity
silverstripe CWE-79
6.1
2021-06-08 CVE-2020-26136 Improper Authentication vulnerability in Silverstripe
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
network
low complexity
silverstripe CWE-287
6.5
2021-06-08 CVE-2020-25817 XXE vulnerability in Silverstripe
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser.
network
low complexity
silverstripe CWE-611
4.8
2021-06-08 CVE-2020-26138 Improper Input Validation vulnerability in Silverstripe
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
network
low complexity
silverstripe CWE-20
5.3
2020-07-15 CVE-2020-9311 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
network
low complexity
silverstripe CWE-79
5.4
2020-07-15 CVE-2020-9309 Unrestricted Upload of File with Dangerous Type vulnerability in Silverstripe Mimevalidator and Recipe
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file).
network
low complexity
silverstripe CWE-434
8.8