Silverstripe
Silverstripe Framework: vulnerabilidades y CVE
Silverstripe Framework tiene 18 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54720 | Media (5.4) | 0.26% | — | 1 jul 2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed. This… |
| CVE-2026-24749 | Media (5.3) | 0.40% | — | 16 abr 2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or… |
| CVE-2025-30148 | Media (5.4) | 0.29% | — | 10 abr 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could… |
| CVE-2024-53277 | Media (5.4) | 0.32% | — | 14 ene 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the… |
| CVE-2024-47605 | Media (5.4) | 1.1% | — | 14 ene 2025 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The… |
| CVE-2024-32981 | Media (5.4) | 0.35% | — | 17 jul 2024 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the… |
| CVE-2023-48714 | Media (4.3) | 0.36% | — | 23 ene 2024 | Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added… |
| CVE-2023-22729 | Media (6.1) | 0.42% | — | 26 abr 2023 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen… |
| CVE-2023-22728 | Media (4.3) | 0.49% | — | 26 abr 2023 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of… |
| CVE-2022-38147 | Media (5.4) | 0.55% | — | 23 nov 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). |
| CVE-2022-38145 | Media (5.4) | 0.63% | — | 23 nov 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view. |
| CVE-2022-37430 | Media (5.4) | 0.55% | — | 23 nov 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). |
| CVE-2022-37429 | Media (5.4) | 0.51% | — | 23 nov 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. |
| CVE-2022-38724 | Media (5.4) | 0.68% | — | 23 nov 2022 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. |
| CVE-2022-38462 | Media (6.1) | 0.50% | — | 22 nov 2022 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. |
| CVE-2022-38148 | Alta (8.8) | 0.77% | — | 21 nov 2022 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. |
| CVE-2022-38146 | Media (5.4) | 0.56% | — | 21 nov 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). |
| CVE-2022-25238 | Media (5.4) | 0.69% | — | 28 jun 2022 | Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the… |