Vulnerabilities > Silverstripe > Low

DATE CVE VULNERABILITY TITLE RISK
2022-06-29 CVE-2022-28803 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).
3.5
2022-06-28 CVE-2022-25238 Cross-site Scripting vulnerability in Silverstripe Framework
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
3.5
2021-06-08 CVE-2020-25817 XXE vulnerability in Silverstripe
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser.
3.5
2020-07-15 CVE-2020-9311 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
3.5
2019-09-26 CVE-2019-14272 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
3.5
2019-09-25 CVE-2019-12203 Session Fixation vulnerability in Silverstripe
SilverStripe through 4.3.3 allows session fixation in the "change password" form.
local
high complexity
silverstripe CWE-384
3.7
2012-08-26 CVE-2010-5092 Credentials Management vulnerability in Silverstripe 2.4.0
The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.
1.9
2012-02-02 CVE-2012-0976 Cross-Site Scripting vulnerability in Silverstripe 2.4.6
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter.
network
high complexity
silverstripe CWE-79
2.1