
silverstripe/framework
packagist · The SilverStripe framework · Repository · Package
Security Advisories for silverstripe/framework in packagist
Moderate
6 months ago
Silverstripe Framework user enumeration via timing attack on login and password reset forms
packagist
silverstripe/framework
Moderate
6 months ago
Silverstripe Framework has a XSS vulnerability in HTML editor
packagist
silverstripe/framework
Low
8 months ago
Reflected Cross Site Scripting (XSS) in error message
packagist
silverstripe/framework
Low
9 months ago
Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message
packagist
silverstripe/framework
Moderate
9 months ago
Silverstripe Framework has a XSS in form messages
packagist
silverstripe/framework
Moderate
9 months ago
Silverstripe Framework has a XSS via insert media remote file oembed
packagist
silverstripe/framework
Moderate
about 1 year ago
Silverstripe uses TinyMCE which allows svg files linked in object tags
packagist
silverstripe/framework
Moderate
about 1 year ago
Silverstripe Framework has a Cross-site Scripting vulnerability with encoded payload
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework has possible denial of service attack vector when flushing
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework may disclose database credentials during connection failure
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework allows upload of dangerous file types
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework vulnerable to member disclosure in login form
packagist
silverstripe/framework
Low
over 1 year ago
silverstripe/framework sends passwords back to browsers under some circumstances
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework uploaded PHP script execution in assets
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework code execution vulnerability
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework BackURL validation bypass with malformed URLs
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential forms
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework Privilege Escalation Risk in Member Edit form
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework's URL parameters `isDev` and `isTest` unguarded
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework SQL injection in full text search
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework users inadvertently passing sensitive data to LoginAttempt
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework CSV Excel Macro Injection
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework vulnerable to user enumeration via timing attack on login and password reset forms
packagist
silverstripe/framework
High
over 1 year ago
silverstripe/framework's User-Agent header not correctly invalidating user session
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework has Cross-site Scripting vulnerability in page history comparison
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework has Cross-site Scripting vulnerability in RedirectorPage
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework has Cross-site Scripting vulnerability in CMSSecurity BackURL
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework has Cross-site Scripting vulnerability in page name
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework member disclosure in login form
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework vulnerable to Cross-site Scripting In `OptionsetField` and `CheckboxSetField`
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework's `Member.Name` is not escaped
packagist
silverstripe/framework
Low
over 1 year ago
silverstripe/framework's pre-existing alc_enc cookies log users in if remember me is disabled
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework missing ACL on reports
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework ChangePasswordForm does not check `Member::canLogIn()`
packagist
silverstripe/framework
Low
over 1 year ago
silverstripe/framework password encryption salt not updated
packagist
silverstripe/framework
Moderate
over 1 year ago
silverstripe/framework ReadOnly transformation for formfields exploitable
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe Missing CSRF protection in login form
packagist
silverstripe/framework
Critical
over 1 year ago
Silverstripe Brute force bypass on default admin
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe Missing security check on dev/build/defaults
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe HtmlEditor embed url sanitisation
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe Form field validation message XSS vulnerability
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe framework is vulnerable to XSS in install.php
packagist
silverstripe/framework
Moderate
over 1 year ago
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe XSS in dev/build returnURL Parameter
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe External redirection risk in Security?ReturnURL
packagist
silverstripe/framework
High
over 1 year ago
Silverstripe X-Forwarded-Host request hostname injection
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe XSS in Director::force_redirect()
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe XSS in TreeDropdownField and TreeMultiSelectField
packagist
silverstripe/framework
Moderate
over 1 year ago
SilverStripe framework XML Quadratic Blowup Attack
packagist
silverstripe/framework
Moderate
over 1 year ago
Silverstripe IE requests not properly behaving with rewritehashlinks
packagist
silverstripe/framework
Moderate
over 1 year ago
Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter
packagist
silverstripe/framework
Low
about 2 years ago
Silverstripe Framework: Members with no password can be created and bypass custom login forms
packagist
silverstripe/framework
Moderate
over 2 years ago
Missing permission check of canView in GridFieldPrintButton
packagist
silverstripe/framework
Moderate
over 2 years ago
Open redirect vulnerability on CMSSecurity relogin screen
packagist
silverstripe/framework
High
almost 3 years ago
Blind SQL Injection via GridFieldSortableHeader
packagist
silverstripe/framework
Moderate
almost 3 years ago
Reflected XSS in querystring parameters
packagist
silverstripe/framework
Moderate
almost 3 years ago
Stored XSS using uppercase characters in HTMLEditor
packagist
silverstripe/framework
Moderate
almost 3 years ago
Silverstripe XSS in shortcodes
packagist
silverstripe/framework, silverstripe/assets
Moderate
over 3 years ago
Stored XSS via HTML fields in SilverStripe Framework
packagist
silverstripe/framework
Moderate
over 3 years ago
Stored XSS in link tags added via XHR in SilverStripe Framework
packagist
silverstripe/framework
Moderate
over 3 years ago
SilverStripe XXE Vulnerability in CSSContentParser
packagist
silverstripe/framework
Moderate
over 3 years ago
SilverStripe Web Cache Poisoning through HTTPRequestBuilder
packagist
silverstripe/framework
High
over 3 years ago
SilverStripe Folders migrated from 3.x may be unsafe to upload to
packagist
silverstripe/assets, silverstripe/userforms, silverstripe/framework
Moderate
over 3 years ago
SilverStripe Denial of Service on flush and development URL tools
packagist
silverstripe/framework
Moderate
over 3 years ago
SilverStripe asset-admin Cross-site Scripting (XSS)
packagist
silverstripe/framework
Moderate
over 3 years ago
Silverstripe Flash Clipboard Reflected XSS
packagist
silverstripe/framework, silverstripe/admin
Moderate
over 3 years ago
Silverstripe CMS Open Redirect
packagist
silverstripe/framework, silverstripe/cms
Low
over 3 years ago
SilverStripe vulnerable to Cross-site Scripting
packagist
silverstripe/framework, silverstripe/cms
Critical
over 3 years ago
Silverstripe Framework SQLi Vulnerability
packagist
silverstripe/framework
Moderate
over 3 years ago
FormField with square brackets in field name skips validation
packagist
silverstripe/framework
Moderate
over 3 years ago
Business Logic Errors in SilverStripe Framework
packagist
silverstripe/framework
Low
almost 6 years ago
SilverStripe Priviledge escalation through cache pollution
packagist
silverstripe/framework
Moderate
almost 6 years ago
Session fixation in change password form
packagist
silverstripe/framework
Critical
almost 6 years ago
Missing warning can lead to unauthenticated admin access in SilverStripe
packagist
silverstripe/framework, silverstripe/cms
Moderate
almost 6 years ago
SilverStripe Versioned Files module Unpublished files are exposed publicly
packagist
silverstripe/framework, symbiote/silverstripe-versionedfiles