Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.34%—Silverstripe VersionedAI28/8/20269/9/2026
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and…
AplazadaAlta (8.8)0.73%—Silverstripe UserformsAISilverstripe CMSAI27/8/20269/9/2026
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to…
AplazadaAlta (7.2)1.0%—Silverstripe Advanced WorkflowAISilverstripeAI27/8/20269/9/2026
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When…
AplazadaMedia (5.4)0.34%—Silverstripe CMSAI6/8/20268/9/2026
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.
AplazadaMedia (5.4)0.26%—Silverstripe CMSAISilverstripe FrameworkAI1/7/20262/7/2026
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed. This issue was fixed in version 6.2.2/
AplazadaMedia (5.3)0.40%—Silverstripe Assets ModuleAISilverstripe FrameworkAI16/4/202617/6/2026
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file…
AnalizadaMedia (5.4)0.29%—Silverstripe Framework10/4/202517/6/2026
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitized…
AplazadaMedia (5.4)0.30%—Silverstripe ElementalAI10/4/202517/6/2026
Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that…
AnalizadaMedia (5.4)0.32%—Silverstripe Framework14/1/202517/6/2026
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the given message. Some form messages include content that the user can provide. There are scenarios in…
AplazadaMedia (5.4)1.1%—Silverstripe FrameworkAI14/1/202517/6/2026
silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on…
AnalizadaMedia (5.4)0.35%—Silverstripe Framework17/7/202417/6/2026
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The…
AnalizadaMedia (4.3)0.40%—Silverstripe Reports17/7/202417/6/2026
silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be accessed by their direct URL by any user who has access to view the reports admin section, even if the `canView()` method for that report returns `false`. This issue has been addressed in…
ModificadaMedia (4.3)0.34%—Silverstripe Admin23/1/202417/6/2026
Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch prior to 2.1.8, users who don't have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form,…
ModificadaMedia (4.3)0.36%—Silverstripe Framework23/1/202417/6/2026
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be…
ModificadaMedia (5.3)0.42%—Silverstripe Graphql23/1/202417/6/2026
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is greater than the number of records per page.…
ModificadaAlta (7.5)0.90%—Silverstripe Graphql16/10/202317/6/2026
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS…
ModificadaMedia (6.1)0.42%—Silverstripe Framework26/4/202317/6/2026
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link. Users should upgrade to…
ModificadaMedia (4.3)0.49%—Silverstripe Framework26/4/202317/6/2026
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users…
ModificadaMedia (5.4)0.39%—Bigfork Silverstripe Form Capture3/4/202317/6/2026
Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Starting in version 0.2.0 and prior to versions 1.0.2, 1.1.0, 2.2.5, and 3.1.1, improper escaping when presenting stored form submissions allowed for an attacker to perform a Cross-Site Scripting attack.…
ModificadaAlta (7.5)1.1%—Silverstripe Graphql16/3/202317/6/2026
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly…
ModificadaCrítica (9.8)0.67%—Webbuildersgroup Silverstripe-kapost-bridge10/2/202317/6/2026
A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affected by this vulnerability is the function index/getPreview of the file code/control/KapostService.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to…
ModificadaAlta (7.5)0.54%—Silverstripe Subsites21/12/202217/6/2026
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
ModificadaMedia (5.4)0.55%—Silverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
ModificadaMedia (5.4)0.56%—Silverstripe23/11/202217/6/2026
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
ModificadaMedia (5.4)0.63%—Silverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.