Technology · Packagist
silverstripe/framework (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 35 vulnerabilities in silverstripe/framework (Packagist): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54720, was published on 1 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About silverstripe/framework (Packagist)
SilverStripe Framework is a PHP-based open-source content management system and web application framework.
Latest silverstripe/framework (Packagist) vulnerabilities
- CVE-2026-54720: Silverstripe Framework XSS in Insert media from web functionalitymediumCVSS 5.4EPSS 0.3%
- Silverstripe Framework user enumeration via timing attack on login and password reset formslowCVSS 3.1
- CVE-2025-30148: Silverstripe Framework has a XSS vulnerability in HTML editorlowCVSS 3.1EPSS 0.3%
- Reflected Cross Site Scripting (XSS) in error messageinfo
- Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error messagelowCVSS 3.1
- CVE-2024-53277: Silverstripe Framework has a XSS in form messageslowCVSS 3.1EPSS 0.3%
- CVE-2024-47605: Silverstripe Framework has a XSS via insert media remote file oembedlowCVSS 3.1EPSS 1.1%
- Silverstripe uses TinyMCE which allows svg files linked in object tagslowCVSS 3.1
- CVE-2024-32981: Silverstripe Framework has a Cross-site Scripting vulnerability with encoded payloadlowCVSS 3.1EPSS 0.4%
- silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential formslowCVSS 3.1
- Silverstripe HtmlEditor embed url sanitisationlowCVSS 3.1
- Silverstripe framework is vulnerable to XSS in install.phplowCVSS 3.1
- Silverstripe XSS in dev/build returnURL ParameterlowCVSS 3.1
- Silverstripe X-Forwarded-Host request hostname injectionlowCVSS 3.1
- Silverstripe XSS in Director::force_redirect()lowCVSS 3.1
- Silverstripe XSS In FormActionlowCVSS 3.1
- Silverstripe XSS In GridField printlowCVSS 3.1
- Silverstripe XSS in TreeDropdownField and TreeMultiSelectFieldlowCVSS 3.1
- SilverStripe framework XML Quadratic Blowup AttacklowCVSS 3.1
- CVE-2023-22728: Missing permission check of canView in GridFieldPrintButtonlowCVSS 3.1EPSS 0.5%
- CVE-2023-22729: Open redirect vulnerability on CMSSecurity relogin screenlowCVSS 3.1EPSS 0.4%
- CVE-2022-38462: Reflected XSS in querystring parameterslowCVSS 3.1EPSS 0.5%
- CVE-2022-37429: Stored XSS using HTMLEditorlowCVSS 3.1EPSS 0.5%
- CVE-2022-37430: Stored XSS using uppercase characters in HTMLEditorlowCVSS 3.1EPSS 0.5%
- CVE-2022-38724: Silverstripe XSS in shortcodeslowCVSS 3.1EPSS 0.7%
Most severe silverstripe/framework (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-54720: Silverstripe Framework XSS in Insert media from web functionalitymediumCVSS 5.4EPSS 0.3%
- CVE-2010-1593: SilverStripe vulnerable to Cross-site ScriptingmediumCVSS 4EPSS 2.6%
- CVE-2019-12204: Missing warning can lead to unauthenticated admin access in SilverStripelowCVSS 3.1EPSS 1.5%
- CVE-2020-26138: FormField with square brackets in field name skips validationlowCVSS 3.1EPSS 1.3%
- CVE-2024-47605: Silverstripe Framework has a XSS via insert media remote file oembedlowCVSS 3.1EPSS 1.1%
- CVE-2021-41559: Quadratic blowup in Convert::xml2array()lowCVSS 3.1EPSS 1.1%
- CVE-2020-25817: SilverStripe XXE Vulnerability in CSSContentParserlowCVSS 3.1EPSS 0.8%
- CVE-2022-25238: Stored XSS via HTML fields in SilverStripe FrameworklowCVSS 3.1EPSS 0.7%
- CVE-2022-38724: Silverstripe XSS in shortcodeslowCVSS 3.1EPSS 0.7%
- CVE-2020-9311: Silverstripe CMS XSS VulnerabilitylowCVSS 3.1EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/silverstripe-framework.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "silverstripe/framework (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/silverstripe-framework, 28 September 2026.