silverstripe/framework Security Advisories for 3.5.2 (25)
- 
                        [MEDIUM] CVE-2025-30148 - XSS vulnerability in HTML editorPKSA-y2dn-63zz-mp8n CVE-2025-30148 GHSA-rhx4-hvx9-j387 Affected version: <5.3.23 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SS-2025-001 - User enumeration via timing attackPKSA-7qg6-pyzm-bc35 GHSA-256q-hx8w-xcqx Affected version: <5.3.23 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2024-53277 - XSS in form messagesPKSA-gr7c-c3q7-zxkd CVE-2024-53277 GHSA-ff6q-3c9c-6cf5 Affected version: <5.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2024-47605 - XSS via insert media remote file oembedPKSA-spqx-5bk6-c9yk CVE-2024-47605 GHSA-7cmp-cgg8-4c82 Affected version: <5.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] SS-2024-002 - Reflected Cross Site Scripting (XSS) in error messagePKSA-24rt-ffr7-cj1w GHSA-74j9-xhqr-6qv3 Affected version: <5.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2024-32981 - XSS Vulnerability with text/html base64-encoded payloadPKSA-jndv-7cgy-xwm3 CVE-2024-32981 GHSA-chx7-9x8h-r5mg Affected version: <5.2.16 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] SS-2024-001 - TinyMCE allows svg files linked in object tagsPKSA-8tf6-2hv5-c6tq GHSA-mqf3-qpc3-g26q Affected version: <5.2.16 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2023-48714 Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleterPKSA-vcdc-4796-kn58 CVE-2023-48714 GHSA-qm2j-qvq3-j29v Affected version: >=3.0.0,<4.0.0|>=4.0.0,<4.13.39|>=5.0.0,<5.1.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] CVE-2023-32302 - Members with no password can be created and bypass custom login formsPKSA-2t2m-vnwy-55q7 CVE-2023-32302 GHSA-36xx-7vf6-7mv3 Affected version: >=3.0.0,<4.13.14|>=5.0.0,<5.0.13 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SilverStripe CSV Excel Macro InjectionPKSA-4npp-z2k1-kdtx CVE-2017-18049 GHSA-2jvj-mhf2-g99w Affected version: >=4.0.0,<4.0.1|>=3.6.0,<3.6.3|<3.5.6 Reported by: 
 GitHub
- 
                        [MEDIUM] Business Logic Errors in SilverStripe FrameworkPKSA-7j38-hj68-r82v CVE-2022-0227 GHSA-32m2-9f76-4gv8 Affected version: <4.10.1 Reported by: 
 GitHub
- 
                        [MEDIUM] CVE-2020-26138 FormField: with square brackets in field name skips validationPKSA-pq7g-1pwh-dw3n CVE-2020-26138 GHSA-7mv4-4xpg-xq44 Affected version: >=3.0.0,<4.0.0|>=4.0.0,<4.7.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2020-9311: Malicious user profile information can cause login form XSSPKSA-34vk-6svm-bpgy CVE-2020-9311 GHSA-2pw2-qpcp-m47x Affected version: >=3.0.0,<3.7.5 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2019-19326: Web Cache Poisoning through HTTPRequestBuilderPKSA-75gp-x5bj-hcwc CVE-2019-19326 GHSA-q9ff-3q93-fm8m Affected version: >=4.0.0,<4.4.7|>=4.5.0,<4.5.4|>=3.0.0,<3.7.5 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Lack of access control on upoaded filesPKSA-5yvt-vswv-zn54 CVE-2019-12245 GHSA-jvx5-rm6q-gx7p Affected version: >=4.4.0,<4.4.4|>=4.0.0,<4.3.6|>=3.7.0,<3.7.4|<3.6.8 Reported by: 
 GitHub
- 
                        [MEDIUM] CVE-2019-12205: Clipboard Reflected XSSPKSA-89c6-sr3z-fq77 CVE-2019-12205 GHSA-rfvw-5848-gxc5 Affected version: >=3.0.0,<3.9.99|>=4.3.0,<4.3.5|>=4.4.0,<4.4.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] CVE-2019-5715: Reflected SQL Injection through Form and DataObjectPKSA-sn55-3v1d-5xkw CVE-2019-5715 GHSA-wvfw-w3x6-g526 Affected version: >=3.0.0,<3.6.7|>=3.7.0,<3.7.3|>=4.0.0,<4.0.7|>=4.1.0,<4.1.5|>=4.2.0,<4.2.4|>=4.3.0,<4.3.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SS-2017-009: Users inadvertently passing sensitive data to LoginAttemptPKSA-drtz-1sqz-9xcw GHSA-vj2j-6g3w-4662 Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3|>=4.0.0,<4.0.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] SS-2017-007: CSV Excel Macro InjectionPKSA-vxjn-1q46-f6sf GHSA-mqjc-x563-c9q8 Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3|>=4.0.0,<4.0.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SS-2017-008: SQL injection in full text search of SilverStripe 4PKSA-374x-kczb-dk1n GHSA-52cw-pvq9-9m5v Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3|>=4.0.0,<4.0.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SS-2017-006: Session user agent change detectionPKSA-qgw5-v9gv-s75z GHSA-m8v7-x398-pxrf Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SS-2017-005: User enumeration via timing attack on login and password reset formsPKSA-95gt-f8d7-9gcg GHSA-g4hp-pfvf-vm5w Affected version: >=3.5.0,<3.5.5|>=3.6.0,<3.6.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SS-2017-002: Member disclosure in login formPKSA-7nk4-stp5-bg39 GHSA-p5h2-vr99-xm99 Affected version: >=3.4.0,<3.4.6|>=3.5.0,<3.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] SS-2017-004: XSS in page history comparisonPKSA-qt6n-rv4n-mdrh GHSA-cwgq-83w5-8jfq Affected version: >=3.4.0,<3.4.6|>=3.5.0,<3.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] SS-2017-003: XSS in RedirectorPagePKSA-c5xx-ym8s-c3ty GHSA-vgxh-x8jv-hmff Affected version: >=3.4.0,<3.4.6|>=3.5.0,<3.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories