Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
silverstripe vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2010-5094
The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x prior to 2.3.7 does not require ADMIN permissions, which allows remote malicious users to delete index.php and "disrupt mod_rewrite-less URL routing."
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
4.3
CVSSv2
CVE-2010-5095
Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.2
5
CVSSv2
CVE-2010-5188
SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
6.8
CVSSv2
CVE-2011-4962
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x prior to 2.4.6 might allow remote malicious users to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.1
Silverstripe Silverstripe 2.4.4
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.5
4.3
CVSSv2
CVE-2010-4822
core/model/MySQLDatabase.php in SilverStripe 2.4.x prior to 2.4.4, when the site is running in "live mode," allows remote malicious users to obtain the SQL queries for a page via the showqueries and ajax parameters.
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.1
4.3
CVSSv2
CVE-2017-5197
There is XSS in SilverStripe CMS prior to 3.4.4 and 3.5.x prior to 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Silverstripe Silverstripe 3.5.0
Silverstripe Silverstripe 3.5.1
Silverstripe Silverstripe
3.5
CVSSv2
CVE-2020-25817
SilverStripe up to and including 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or ...
Silverstripe Silverstripe
Silverstripe Silverstripe 4.6.0
4.3
CVSSv2
CVE-2017-18049
In the CSV export feature of SilverStripe prior to 3.5.6, 3.6.x prior to 3.6.3, and 4.x prior to 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For ex...
Silverstripe Silverstripe
Silverstripe Silverstripe 4.0.0
5
CVSSv2
CVE-2017-12849
Response discrepancy in the login and password reset forms in SilverStripe CMS prior to 3.5.5 and 3.6.x prior to 3.6.1 allows remote malicious users to enumerate users via timing attacks.
Silverstripe Silverstripe 3.6.0
Silverstripe Silverstripe
6.4
CVSSv2
CVE-2022-24444
Silverstripe silverstripe/framework up to and including 4.10 allows Session Fixation.
Silverstripe Silverstripe 2.5.0
Silverstripe Silverstripe
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27975
CVE-2024-2961
CVE-2024-20380
XML injection
HTML injection
CVE-2024-29204
CVE-2023-51795
memory leak
CVE-2024-3470
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »