<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Silverstripe CMS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/silverstripe.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/silverstripe-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Silverstripe CMS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2023-40180 – silverstripe-graphql is a package which serves Silverstripe data in GraphQL repr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40180</guid>
    <pubDate>Mon, 16 Oct 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40180</strong></p>
  <p>silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28104 – `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28104</guid>
    <pubDate>Thu, 16 Mar 2023 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28104</strong></p>
  <p>`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly large/complex graphql schemas. Users should upgrade to `silverstripe/graphql` 4.2.3 or 4…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42949 – Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42949</guid>
    <pubDate>Wed, 21 Dec 2022 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42949</strong></p>
  <p>Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38148 – Silverstripe silverstripe/framework through 4.11 allows SQL Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38148</guid>
    <pubDate>Mon, 21 Nov 2022 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38148</strong></p>
  <p>Silverstripe silverstripe/framework through 4.11 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9309 – Silverstripe CMS through 4.5 can be susceptible to script execution from malicio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9309</guid>
    <pubDate>Wed, 15 Jul 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9309</strong></p>
  <p>Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as protected or draft files are allowed by default for authorised users only, but can also…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-6164 – In SilverStripe through 4.5.0, a specific URL path configured by default through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6164</guid>
    <pubDate>Wed, 15 Jul 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-6164</strong></p>
  <p>In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL path is limited to execution in a CLI context, and is not known to present a vulnerability through web-based access. As…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9280 – In SilverStripe through 4.5, files uploaded via Forms to folders migrated from S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9280</guid>
    <pubDate>Wed, 15 Apr 2020 21:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9280</strong></p>
  <p>In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12437 – In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not complet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12437</guid>
    <pubDate>Wed, 19 Feb 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12437</strong></p>
  <p>In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12204 – In SilverStripe through 4.3.3, a missing warning about leaving install.php in a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12204</guid>
    <pubDate>Wed, 25 Sep 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12204</strong></p>
  <p>In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12149 – SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12149</guid>
    <pubDate>Tue, 11 Jun 2019 22:29:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12149</strong></p>
  <p>SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5715 – All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of Sil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5715</guid>
    <pubDate>Thu, 11 Apr 2019 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5715</strong></p>
  <p>All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4960 – SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4960</guid>
    <pubDate>Mon, 17 Sep 2012 17:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4960</strong></p>
  <p>SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6753 – SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6753</guid>
    <pubDate>Mon, 27 Apr 2009 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6753</strong></p>
  <p>SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to AjaxUniqueTextField.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1433 – SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1433</guid>
    <pubDate>Fri, 24 Apr 2009 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1433</strong></p>
  <p>SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-2321 – Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2321</guid>
    <pubDate>Fri, 27 Apr 2007 00:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-2321</strong></p>
  <p>Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2321">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
