The CVE-2026-54717 vulnerability is a cross-site scripting issue in Silverstripe CMS prior to version 6.2.1. The vulnerability occurs when page titles are rendered into breadcrumbs without proper escaping when viewed via the page list view. This allows an attacker to inject malicious JavaScript code, potentially leading to unauthorized actions or data theft. Affected product deployments should be reviewed [truncated]
CVE-2017-5197 is a cross-site scripting issue in SilverStripe CMS affecting page-name handling. The vulnerability is described as reachable over the network and requiring user interaction, with an attacker able to influence a page name so that script executes in a victim’s browser context. The published advisory says the issue is fixed in SilverStripe CMS 3.4.4 and 3.5.2, and gives a malformed SVG/event-h [truncated]