Vulnerabilities > Silverstripe > Silverstripe > 3.6.8

DATE CVE VULNERABILITY TITLE RISK
2022-11-23 CVE-2022-37421 Cross-site Scripting vulnerability in Silverstripe
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
network
low complexity
silverstripe CWE-79
5.4
2022-06-29 CVE-2022-28803 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).
3.5
2022-06-28 CVE-2021-41559 XML Entity Expansion vulnerability in Silverstripe
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
network
low complexity
silverstripe CWE-776
6.5
2021-10-07 CVE-2021-36150 Cross-site Scripting vulnerability in Silverstripe
SilverStripe Framework through 4.8.1 allows XSS.
4.3
2021-06-08 CVE-2020-26136 Improper Authentication vulnerability in Silverstripe
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
network
low complexity
silverstripe CWE-287
4.0
2021-06-08 CVE-2020-25817 XXE vulnerability in Silverstripe
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser.
3.5
2021-06-08 CVE-2020-26138 Improper Input Validation vulnerability in Silverstripe
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
network
low complexity
silverstripe CWE-20
5.0
2020-07-15 CVE-2020-9311 Cross-site Scripting vulnerability in Silverstripe
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
3.5
2019-09-26 CVE-2019-16409 Information Exposure vulnerability in multiple products
In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL.
network
low complexity
symbiote silverstripe CWE-200
5.0
2019-09-26 CVE-2019-12617 Unspecified vulnerability in Silverstripe
In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pollution.
network
low complexity
silverstripe
4.0