Vulnerabilities > Silverstripe > Silverstripe > 3.0.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-11-23 | CVE-2022-37421 | Cross-site Scripting vulnerability in Silverstripe Silverstripe silverstripe/cms through 4.11.0 allows XSS. | 5.4 |
2022-06-29 | CVE-2022-28803 | Cross-site Scripting vulnerability in Silverstripe In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR). | 5.4 |
2022-06-28 | CVE-2021-41559 | XML Entity Expansion vulnerability in Silverstripe Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document. | 6.5 |
2021-10-07 | CVE-2021-28661 | Incorrect Authorization vulnerability in Silverstripe Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass. | 4.3 |
2021-10-07 | CVE-2021-36150 | Cross-site Scripting vulnerability in Silverstripe SilverStripe Framework through 4.8.1 allows XSS. | 6.1 |
2021-06-08 | CVE-2020-26136 | Improper Authentication vulnerability in Silverstripe In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. | 6.5 |
2021-06-08 | CVE-2020-25817 | XXE vulnerability in Silverstripe SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. | 4.8 |
2021-06-08 | CVE-2020-26138 | Improper Input Validation vulnerability in Silverstripe In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. | 5.3 |
2020-07-15 | CVE-2020-9311 | Cross-site Scripting vulnerability in Silverstripe In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs. | 5.4 |
2020-07-15 | CVE-2020-6164 | Unspecified vulnerability in Silverstripe In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. | 7.5 |