PatchSiren

silverstripe CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH silverstripe CVE published 2026-08-27

CVE-2026-54721

CVE-2026-54721 debrief based on the supplied source corpus. The vulnerability is a server-side code execution issue in Silverstripe UserForms, affecting versions 6.0.0 through 6.4.8, 7.0.0 through 7.0.6, and 7.1.0. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code on the server, compromising confidentiality, integrity, and av [truncated]

HIGH silverstripe CVE published 2026-08-27

CVE-2026-54718

The Silverstripe Advanced Workflow module, used for highly configurable step-based workflows, contains a vulnerability that allows for arbitrary code execution. This is achieved through a specially crafted server-side template payload in the NotifyUsersWorkflowAction.EmailTemplate field, requiring permission to author the advanced workflow email template. The vulnerability has a HIGH CVSS score of 7.2, in [truncated]

MEDIUM silverstripe CVE published 2026-08-06

CVE-2026-54717

CVE-2026-54717 is a medium-severity vulnerability in Silverstripe CMS, affecting page breadcrumbs in the CMS, which are vulnerable to cross-site scripting when viewed using the page list view. This issue is fixed in version 6.2.1. The vulnerability allows an attacker to inject malicious scripts into the breadcrumb trail, potentially leading to unauthorized actions or data breaches. Defenders should assess [truncated]

MEDIUM Silverstripe CVE published 2017-03-06

CVE-2017-5197

CVE-2017-5197 is a cross-site scripting issue in SilverStripe CMS affecting page-name handling. The vulnerability is described as reachable over the network and requiring user interaction, with an attacker able to influence a page name so that script executes in a victim’s browser context. The published advisory says the issue is fixed in SilverStripe CMS 3.4.4 and 3.5.2, and gives a malformed SVG/event-h [truncated]