Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
silverstripe vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-38462
Silverstripe silverstripe/framework up to and including 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
Silverstripe Framework
4.3
CVSSv3
CVE-2022-29858
Silverstripe silverstripe/assets up to and including 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
Silverstripe Assets
5.4
CVSSv3
CVE-2022-38145
Silverstripe silverstripe/framework up to and including 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
Silverstripe Framework
5.4
CVSSv3
CVE-2022-38146
Silverstripe silverstripe/framework up to and including 4.11 allows XSS (issue 2 of 3).
Silverstripe Framework
5.4
CVSSv3
CVE-2022-38147
Silverstripe silverstripe/framework up to and including 4.11 allows XSS (issue 3 of 3).
Silverstripe Framework
8.8
CVSSv3
CVE-2022-38148
Silverstripe silverstripe/framework up to and including 4.11 allows SQL Injection.
Silverstripe Framework
7.5
CVSSv3
CVE-2022-42949
Silverstripe silverstripe/subsites up to and including 2.6.0 has Insecure Permissions.
Silverstripe Subsites
4.3
CVSSv3
CVE-2023-48714
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocomplete...
Silverstripe Framework
4.3
CVSSv3
CVE-2023-49783
Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch before 1.13.19 and on the 2.x branch before 2.1.8, users who don't have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or d...
Silverstripe Admin
7.5
CVSSv3
CVE-2023-40180
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed grap...
Silverstripe Graphql
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »