Silverstripe / Framework
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-30148 | Silverstripe Framework has a XSS vulnerability in HTML editor | MEDIUM | 5.4 | Apr 10, 2025 |
| CVE-2024-53277 | Cross-site Scripting in form messages in silverstripe framework | MEDIUM | 5.4 | Jan 14, 2025 |
| CVE-2024-32981 | Cross-site Scripting vulnerability with encoded payload in silverstripe/framework | MEDIUM | 5.3 | Jul 17, 2024 |
| CVE-2023-48714 | Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter | MEDIUM | 4.3 | Jan 23, 2024 |
| CVE-2023-22729 | Silverstripe Framework has open redirect vulnerability on CMSSecurity relogin screen | MEDIUM | 6.1 | Apr 26, 2023 |
| CVE-2023-22728 | Silverstripe Framework has missing permission check of canView in GridFieldPrintButton | MEDIUM | 4.3 | Apr 26, 2023 |
| CVE-2022-38147 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). | MEDIUM | 5.4 | Nov 23, 2022 |
| CVE-2022-38145 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and ge… | MEDIUM | 5.4 | Nov 23, 2022 |
| CVE-2022-37430 | Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). | MEDIUM | 5.4 | Nov 23, 2022 |
| CVE-2022-37429 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL… | MEDIUM | 5.4 | Nov 23, 2022 |
| CVE-2022-38724 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. | MEDIUM | 5.4 | Nov 22, 2022 |
| CVE-2022-38462 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | MEDIUM | 6.1 | Nov 22, 2022 |
| CVE-2022-38148 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | HIGH | 8.8 | Nov 21, 2022 |
| CVE-2022-38146 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). | MEDIUM | 5.4 | Nov 21, 2022 |
| CVE-2022-25238 | Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS u… | MEDIUM | 5.4 | Jun 28, 2022 |
Showing 1 to 15 of 15 CVEs