Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
silverstripe vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-5094
The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x prior to 2.3.7 does not require ADMIN permissions, which allows remote malicious users to delete index.php and "disrupt mod_rewrite-less URL routing."
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
NA
CVE-2011-4962
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x prior to 2.4.6 might allow remote malicious users to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.1
Silverstripe Silverstripe 2.4.4
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.5
NA
CVE-2010-5095
Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.2
NA
CVE-2010-5188
SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
NA
CVE-2010-4822
core/model/MySQLDatabase.php in SilverStripe 2.4.x prior to 2.4.4, when the site is running in "live mode," allows remote malicious users to obtain the SQL queries for a page via the showqueries and ajax parameters.
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.1
6.1
CVSSv3
CVE-2017-5197
There is XSS in SilverStripe CMS prior to 3.4.4 and 3.5.x prior to 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Silverstripe Silverstripe 3.5.0
Silverstripe Silverstripe 3.5.1
Silverstripe Silverstripe
6.5
CVSSv3
CVE-2022-24444
Silverstripe silverstripe/framework up to and including 4.10 allows Session Fixation.
Silverstripe Silverstripe 2.5.0
Silverstripe Silverstripe
9.8
CVSSv3
CVE-2019-5715
All versions of SilverStripe 3 before 3.6.7 and 3.7.3, and all versions of SilverStripe 4 before 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
Silverstripe Silverstripe 4.3.0
Silverstripe Silverstripe
6.5
CVSSv3
CVE-2020-26136
In SilverStripe up to and including 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
Silverstripe Silverstripe
Silverstripe Silverstripe 4.6.0
5.3
CVSSv3
CVE-2020-26138
In SilverStripe up to and including 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
Silverstripe Silverstripe
Silverstripe Silverstripe 4.6.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »