Vulnerabilities > Silverstripe > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-16 | CVE-2023-40180 | Unspecified vulnerability in Silverstripe Graphql silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. | 7.5 |
2023-03-16 | CVE-2023-28104 | Allocation of Resources Without Limits or Throttling vulnerability in Silverstripe Graphql 4.1.1/4.2.2 `silverstripe/graphql` serves Silverstripe data as GraphQL representations. | 7.5 |
2022-12-21 | CVE-2022-42949 | Incorrect Permission Assignment for Critical Resource vulnerability in Silverstripe Subsites Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. | 7.5 |
2022-11-21 | CVE-2022-38148 | SQL Injection vulnerability in Silverstripe Framework Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | 8.8 |
2020-07-15 | CVE-2020-9309 | Unrestricted Upload of File with Dangerous Type vulnerability in Silverstripe Mimevalidator and Recipe Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). | 8.8 |
2020-07-15 | CVE-2020-6164 | Unspecified vulnerability in Silverstripe In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. | 7.5 |
2020-04-15 | CVE-2020-9280 | Unrestricted Upload of File with Dangerous Type vulnerability in Silverstripe In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. | 7.5 |
2020-02-19 | CVE-2019-12437 | Cross-Site Request Forgery (CSRF) vulnerability in Silverstripe In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations, | 8.8 |