Product:

Silverstripe

(Silverstripe)
Date Id Summary Products Score Patch Annotated
2022-06-28 CVE-2021-41559 Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document. Silverstripe 6.5
2022-11-23 CVE-2022-37421 Silverstripe silverstripe/cms through 4.11.0 allows XSS. Silverstripe 5.4
2022-06-28 CVE-2022-24444 Silverstripe silverstripe/framework through 4.10 allows Session Fixation. Silverstripe 6.5
2022-06-29 CVE-2022-28803 In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR). Silverstripe 5.4
2021-10-07 CVE-2021-36150 SilverStripe Framework through 4.8.1 allows XSS. Silverstripe 6.1
2021-10-07 CVE-2021-28661 Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass. Silverstripe 4.3
2019-09-26 CVE-2019-16409 In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users who upgrade from SilverStripe 3.x to 4.x and had Versioned Files installed have no further need for this module, because the 4.x release has built-in versioning. However, nothing in the upgrade process automates the... Silverstripe, Versionedfiles 5.3
2020-07-15 CVE-2020-6164 In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL path is limited to execution in a CLI context, and is not known to present a vulnerability through web-based access. As a side-effect, this preconfigured path also blocks the creation of other resources on this path... Silverstripe 7.5
2021-06-08 CVE-2020-25817 SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID... Silverstripe 4.8
2021-06-08 CVE-2020-26138 In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. Silverstripe 5.3