Vulnerabilities > Silverstripe > Silverstripe > 3.4.4

DATE CVE VULNERABILITY TITLE RISK
2017-10-12 CVE-2017-12849 Information Exposure vulnerability in Silverstripe
Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.
network
low complexity
silverstripe CWE-200
5.0
2017-09-15 CVE-2017-14498 Cross-site Scripting vulnerability in Silverstripe
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.
4.3