Vulnerabilities > Silverstripe > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-40180 Unspecified vulnerability in Silverstripe Graphql
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations.
network
low complexity
silverstripe
7.5
2023-03-16 CVE-2023-28104 Allocation of Resources Without Limits or Throttling vulnerability in Silverstripe Graphql 4.1.1/4.2.2
`silverstripe/graphql` serves Silverstripe data as GraphQL representations.
network
low complexity
silverstripe CWE-770
7.5
2022-12-21 CVE-2022-42949 Incorrect Permission Assignment for Critical Resource vulnerability in Silverstripe Subsites
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
network
low complexity
silverstripe CWE-732
7.5
2022-11-21 CVE-2022-38148 SQL Injection vulnerability in Silverstripe Framework
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
network
low complexity
silverstripe CWE-89
8.8
2020-07-15 CVE-2020-9309 Unrestricted Upload of File with Dangerous Type vulnerability in Silverstripe Mimevalidator and Recipe
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file).
network
low complexity
silverstripe CWE-434
8.8
2020-07-15 CVE-2020-6164 Unspecified vulnerability in Silverstripe
In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application.
network
low complexity
silverstripe
7.5
2020-04-15 CVE-2020-9280 Unrestricted Upload of File with Dangerous Type vulnerability in Silverstripe
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead.
network
low complexity
silverstripe CWE-434
7.5
2020-02-19 CVE-2019-12437 Cross-Site Request Forgery (CSRF) vulnerability in Silverstripe
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
network
low complexity
silverstripe CWE-352
8.8