Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
silverstripe vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-5093
Member_ProfileForm in security/Member.php in SilverStripe 2.3.x prior to 2.3.7 allows remote malicious users to hijack user accounts by saving data using the email address (ID) of another user.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.6
NA
CVE-2011-4962
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x prior to 2.4.6 might allow remote malicious users to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.1
Silverstripe Silverstripe 2.4.4
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.5
NA
CVE-2010-5095
Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.2
NA
CVE-2010-5188
SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
NA
CVE-2010-4822
core/model/MySQLDatabase.php in SilverStripe 2.4.x prior to 2.4.4, when the site is running in "live mode," allows remote malicious users to obtain the SQL queries for a page via the showqueries and ajax parameters.
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.1
6.1
CVSSv3
CVE-2017-5197
There is XSS in SilverStripe CMS prior to 3.4.4 and 3.5.x prior to 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Silverstripe Silverstripe 3.5.0
Silverstripe Silverstripe 3.5.1
Silverstripe Silverstripe
6.1
CVSSv3
CVE-2015-8606
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework prior to 3.1.16 and 3.2.x prior to 3.2.1 allow remote malicious users to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/fie...
Silverstripe Silverstripe
Silverstripe Silverstripe 3.2.0
6.5
CVSSv3
CVE-2022-24444
Silverstripe silverstripe/framework up to and including 4.10 allows Session Fixation.
Silverstripe Silverstripe 2.5.0
Silverstripe Silverstripe
6.5
CVSSv3
CVE-2020-26136
In SilverStripe up to and including 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
Silverstripe Silverstripe
Silverstripe Silverstripe 4.6.0
4.8
CVSSv3
CVE-2020-25817
SilverStripe up to and including 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or ...
Silverstripe Silverstripe
Silverstripe Silverstripe 4.6.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
XXE
CVE-2024-34490
SQL injection
CVE-2024-34488
CVE-2024-4507
CVE-2023-7028
CVE-2024-23187
TCP
CVE-2024-4439
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »