Vulnerabilities > Silverstripe > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-07 CVE-2021-36150 Cross-site Scripting vulnerability in Silverstripe
SilverStripe Framework through 4.8.1 allows XSS.
network
low complexity
silverstripe CWE-79
6.1
2021-06-08 CVE-2020-26136 Improper Authentication vulnerability in Silverstripe
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
network
low complexity
silverstripe CWE-287
6.5
2021-06-08 CVE-2020-25817 XXE vulnerability in Silverstripe
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser.
network
low complexity
silverstripe CWE-611
4.8
2021-06-08 CVE-2020-26138 Improper Input Validation vulnerability in Silverstripe
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
network
low complexity
silverstripe CWE-20
5.3
2020-07-15 CVE-2020-9311 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
network
low complexity
silverstripe CWE-79
5.4
2020-07-15 CVE-2020-6165 Incorrect Default Permissions vulnerability in Silverstripe
SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set.
network
low complexity
silverstripe CWE-276
5.3
2020-07-15 CVE-2019-19326 HTTP Request Smuggling vulnerability in Silverstripe
Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning.
network
high complexity
silverstripe CWE-444
5.9
2020-02-19 CVE-2019-12246 Cross-Site Request Forgery (CSRF) vulnerability in Silverstripe
SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.
network
low complexity
silverstripe CWE-352
4.3
2020-02-17 CVE-2019-19325 Cross-site Scripting vulnerability in Silverstripe
SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms.
network
low complexity
silverstripe CWE-79
6.1
2019-09-26 CVE-2019-16409 In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL.
network
low complexity
symbiote silverstripe
5.3