{"schema_version":1,"title":"silverstripe/framework (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 35 vulnerabilities in silverstripe/framework (Packagist): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54720, was published on 1 July 2026.","url":"https://junglewise.ai/threats/technologies/silverstripe-framework","json_url":"https://junglewise.ai/threats/technologies/silverstripe-framework.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/silverstripe-framework","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":35,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":1},"latest":[{"cve":"CVE-2026-54720","cvss":5.4,"epss":0.0026,"slug":"cve-2026-54720-silverstripe-framework-xss-in-insert-media-from-web-functionality","title":"Silverstripe Framework XSS in Insert media from web functionality","severity":"medium","exploited":false,"published_at":"2026-07-01T21:17:03.417+00:00","url":"https://junglewise.ai/threats/cve-2026-54720-silverstripe-framework-xss-in-insert-media-from-web-functionality"},{"cvss":3.1,"slug":"silverstripe-framework-user-enumeration-via-timing-attack-on-login-and-ffb66d1a","title":"Silverstripe Framework user enumeration via timing attack on login and password reset forms","severity":"low","exploited":false,"published_at":"2025-04-10T20:12:55+00:00","url":"https://junglewise.ai/threats/silverstripe-framework-user-enumeration-via-timing-attack-on-login-and-ffb66d1a"},{"cve":"CVE-2025-30148","cvss":3.1,"epss":0.0029,"slug":"cve-2025-30148-silverstripe-framework-has-a-xss-vulnerability-in-html-editor","title":"Silverstripe Framework has a XSS vulnerability in HTML editor","severity":"low","exploited":false,"published_at":"2025-04-10T13:39:11+00:00","url":"https://junglewise.ai/threats/cve-2025-30148-silverstripe-framework-has-a-xss-vulnerability-in-html-editor"},{"slug":"reflected-cross-site-scripting-xss-in-error-message-34236f6e","title":"Reflected Cross Site Scripting (XSS) in error message","severity":"info","exploited":false,"published_at":"2025-01-23T18:01:26+00:00","url":"https://junglewise.ai/threats/reflected-cross-site-scripting-xss-in-error-message-34236f6e"},{"cvss":3.1,"slug":"silverstripe-framework-has-a-reflected-cross-site-scripting-xss-in-250a177b","title":"Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message","severity":"low","exploited":false,"published_at":"2025-01-14T22:19:06+00:00","url":"https://junglewise.ai/threats/silverstripe-framework-has-a-reflected-cross-site-scripting-xss-in-250a177b"},{"cve":"CVE-2024-53277","cvss":3.1,"epss":0.0032,"slug":"cve-2024-53277-silverstripe-framework-has-a-xss-in-form-messages","title":"Silverstripe Framework has a XSS in form messages","severity":"low","exploited":false,"published_at":"2025-01-14T22:18:59+00:00","url":"https://junglewise.ai/threats/cve-2024-53277-silverstripe-framework-has-a-xss-in-form-messages"},{"cve":"CVE-2024-47605","cvss":3.1,"epss":0.0115,"slug":"cve-2024-47605-silverstripe-framework-has-a-xss-via-insert-media-remote-file","title":"Silverstripe Framework has a XSS via insert media remote file oembed","severity":"low","exploited":false,"published_at":"2025-01-14T22:18:52+00:00","url":"https://junglewise.ai/threats/cve-2024-47605-silverstripe-framework-has-a-xss-via-insert-media-remote-file"},{"cvss":3.1,"slug":"silverstripe-uses-tinymce-which-allows-svg-files-linked-in-object-tags-cf1a5101","title":"Silverstripe uses TinyMCE which allows svg files linked in object tags","severity":"low","exploited":false,"published_at":"2024-07-17T16:00:48+00:00","url":"https://junglewise.ai/threats/silverstripe-uses-tinymce-which-allows-svg-files-linked-in-object-tags-cf1a5101"},{"cve":"CVE-2024-32981","cvss":3.1,"epss":0.0035,"slug":"cve-2024-32981-silverstripe-framework-has-a-cross-site-scripting-vulnerability","title":"Silverstripe Framework has a Cross-site Scripting vulnerability with encoded payload","severity":"low","exploited":false,"published_at":"2024-07-17T14:27:37+00:00","url":"https://junglewise.ai/threats/cve-2024-32981-silverstripe-framework-has-a-cross-site-scripting-vulnerability"},{"cvss":3.1,"slug":"silverstripe-framework-s-install-php-script-discloses-sensitive-data-by-ee02f186","title":"silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential forms","severity":"low","exploited":false,"published_at":"2024-05-27T22:54:06+00:00","url":"https://junglewise.ai/threats/silverstripe-framework-s-install-php-script-discloses-sensitive-data-by-ee02f186"},{"cvss":3.1,"slug":"silverstripe-htmleditor-embed-url-sanitisation-3555f639","title":"Silverstripe HtmlEditor embed url sanitisation","severity":"low","exploited":false,"published_at":"2024-05-23T18:14:45+00:00","url":"https://junglewise.ai/threats/silverstripe-htmleditor-embed-url-sanitisation-3555f639"},{"cvss":3.1,"slug":"silverstripe-framework-is-vulnerable-to-xss-in-install-php-4fc7252e","title":"Silverstripe framework is vulnerable to XSS in install.php","severity":"low","exploited":false,"published_at":"2024-05-23T17:27:19+00:00","url":"https://junglewise.ai/threats/silverstripe-framework-is-vulnerable-to-xss-in-install-php-4fc7252e"},{"cvss":3.1,"slug":"silverstripe-xss-in-dev-build-returnurl-parameter-0477dfec","title":"Silverstripe XSS in dev/build returnURL Parameter","severity":"low","exploited":false,"published_at":"2024-05-23T17:15:09+00:00","url":"https://junglewise.ai/threats/silverstripe-xss-in-dev-build-returnurl-parameter-0477dfec"},{"cvss":3.1,"slug":"silverstripe-x-forwarded-host-request-hostname-injection-48e9e9a1","title":"Silverstripe X-Forwarded-Host request hostname injection","severity":"low","exploited":false,"published_at":"2024-05-23T16:59:25+00:00","url":"https://junglewise.ai/threats/silverstripe-x-forwarded-host-request-hostname-injection-48e9e9a1"},{"cvss":3.1,"slug":"silverstripe-xss-in-director-force-redirect-763fd321","title":"Silverstripe XSS in Director::force_redirect()","severity":"low","exploited":false,"published_at":"2024-05-23T16:48:11+00:00","url":"https://junglewise.ai/threats/silverstripe-xss-in-director-force-redirect-763fd321"},{"cvss":3.1,"slug":"silverstripe-xss-in-formaction-9b461571","title":"Silverstripe XSS In FormAction","severity":"low","exploited":false,"published_at":"2024-05-23T15:23:50+00:00","url":"https://junglewise.ai/threats/silverstripe-xss-in-formaction-9b461571"},{"cvss":3.1,"slug":"silverstripe-xss-in-gridfield-print-16f6be91","title":"Silverstripe XSS In GridField print","severity":"low","exploited":false,"published_at":"2024-05-23T15:00:45+00:00","url":"https://junglewise.ai/threats/silverstripe-xss-in-gridfield-print-16f6be91"},{"cvss":3.1,"slug":"silverstripe-xss-in-treedropdownfield-and-treemultiselectfield-d16a6fce","title":"Silverstripe XSS in TreeDropdownField and TreeMultiSelectField","severity":"low","exploited":false,"published_at":"2024-05-23T14:57:18+00:00","url":"https://junglewise.ai/threats/silverstripe-xss-in-treedropdownfield-and-treemultiselectfield-d16a6fce"},{"cvss":3.1,"slug":"silverstripe-framework-xml-quadratic-blowup-attack-91dbe008","title":"SilverStripe framework XML Quadratic Blowup Attack","severity":"low","exploited":false,"published_at":"2024-05-23T14:49:39+00:00","url":"https://junglewise.ai/threats/silverstripe-framework-xml-quadratic-blowup-attack-91dbe008"},{"cve":"CVE-2023-22728","cvss":3.1,"epss":0.0049,"slug":"cve-2023-22728-missing-permission-check-of-canview-in-gridfieldprintbutton","title":"Missing permission check of canView in GridFieldPrintButton","severity":"low","exploited":false,"published_at":"2023-04-26T19:47:07+00:00","url":"https://junglewise.ai/threats/cve-2023-22728-missing-permission-check-of-canview-in-gridfieldprintbutton"},{"cve":"CVE-2023-22729","cvss":3.1,"epss":0.0042,"slug":"cve-2023-22729-open-redirect-vulnerability-on-cmssecurity-relogin-screen","title":"Open redirect vulnerability on CMSSecurity relogin screen","severity":"low","exploited":false,"published_at":"2023-04-26T19:46:30+00:00","url":"https://junglewise.ai/threats/cve-2023-22729-open-redirect-vulnerability-on-cmssecurity-relogin-screen"},{"cve":"CVE-2022-38462","cvss":3.1,"epss":0.005,"slug":"cve-2022-38462-reflected-xss-in-querystring-parameters","title":"Reflected XSS in querystring parameters","severity":"low","exploited":false,"published_at":"2022-11-21T23:59:56+00:00","url":"https://junglewise.ai/threats/cve-2022-38462-reflected-xss-in-querystring-parameters"},{"cve":"CVE-2022-37429","cvss":3.1,"epss":0.0051,"slug":"cve-2022-37429-stored-xss-using-htmleditor","title":"Stored XSS using HTMLEditor","severity":"low","exploited":false,"published_at":"2022-11-21T23:59:47+00:00","url":"https://junglewise.ai/threats/cve-2022-37429-stored-xss-using-htmleditor"},{"cve":"CVE-2022-37430","cvss":3.1,"epss":0.0055,"slug":"cve-2022-37430-stored-xss-using-uppercase-characters-in-htmleditor","title":"Stored XSS using uppercase characters in HTMLEditor","severity":"low","exploited":false,"published_at":"2022-11-21T23:59:38+00:00","url":"https://junglewise.ai/threats/cve-2022-37430-stored-xss-using-uppercase-characters-in-htmleditor"},{"cve":"CVE-2022-38724","cvss":3.1,"epss":0.0068,"slug":"cve-2022-38724-silverstripe-xss-in-shortcodes","title":"Silverstripe XSS in shortcodes","severity":"low","exploited":false,"published_at":"2022-11-21T23:58:20+00:00","url":"https://junglewise.ai/threats/cve-2022-38724-silverstripe-xss-in-shortcodes"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"silverstripe/framework (Packagist)","slug":"silverstripe-framework","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"description":"SilverStripe Framework is a PHP-based open-source content management system and web application framework.","url":"https://junglewise.ai/threats/technologies/silverstripe-framework"},"most_severe":[{"cve":"CVE-2026-54720","cvss":5.4,"epss":0.0026,"slug":"cve-2026-54720-silverstripe-framework-xss-in-insert-media-from-web-functionality","title":"Silverstripe Framework XSS in Insert media from web functionality","severity":"medium","exploited":false,"published_at":"2026-07-01T21:17:03.417+00:00","url":"https://junglewise.ai/threats/cve-2026-54720-silverstripe-framework-xss-in-insert-media-from-web-functionality"},{"cve":"CVE-2010-1593","cvss":4,"epss":0.026,"slug":"cve-2010-1593-silverstripe-vulnerable-to-cross-site-scripting","title":"SilverStripe vulnerable to Cross-site Scripting","severity":"medium","exploited":false,"published_at":"2022-05-14T02:45:01+00:00","url":"https://junglewise.ai/threats/cve-2010-1593-silverstripe-vulnerable-to-cross-site-scripting"},{"cve":"CVE-2019-12204","cvss":3.1,"epss":0.0146,"slug":"cve-2019-12204-missing-warning-can-lead-to-unauthenticated-admin-access-in","title":"Missing warning can lead to unauthenticated admin access in SilverStripe","severity":"low","exploited":false,"published_at":"2019-11-12T23:01:25+00:00","url":"https://junglewise.ai/threats/cve-2019-12204-missing-warning-can-lead-to-unauthenticated-admin-access-in"},{"cve":"CVE-2020-26138","cvss":3.1,"epss":0.0134,"slug":"cve-2020-26138-formfield-with-square-brackets-in-field-name-skips-validation","title":"FormField with square brackets in field name skips validation","severity":"low","exploited":false,"published_at":"2022-03-26T00:14:34+00:00","url":"https://junglewise.ai/threats/cve-2020-26138-formfield-with-square-brackets-in-field-name-skips-validation"},{"cve":"CVE-2024-47605","cvss":3.1,"epss":0.0115,"slug":"cve-2024-47605-silverstripe-framework-has-a-xss-via-insert-media-remote-file","title":"Silverstripe Framework has a XSS via insert media remote file oembed","severity":"low","exploited":false,"published_at":"2025-01-14T22:18:52+00:00","url":"https://junglewise.ai/threats/cve-2024-47605-silverstripe-framework-has-a-xss-via-insert-media-remote-file"},{"cve":"CVE-2021-41559","cvss":3.1,"epss":0.0106,"slug":"cve-2021-41559-quadratic-blowup-in-convert-xml2array","title":"Quadratic blowup in Convert::xml2array()","severity":"low","exploited":false,"published_at":"2022-06-29T22:39:50+00:00","url":"https://junglewise.ai/threats/cve-2021-41559-quadratic-blowup-in-convert-xml2array"},{"cve":"CVE-2020-25817","cvss":3.1,"epss":0.0082,"slug":"cve-2020-25817-silverstripe-xxe-vulnerability-in-csscontentparser","title":"SilverStripe XXE Vulnerability in CSSContentParser","severity":"low","exploited":false,"published_at":"2022-05-24T19:04:19+00:00","url":"https://junglewise.ai/threats/cve-2020-25817-silverstripe-xxe-vulnerability-in-csscontentparser"},{"cve":"CVE-2022-25238","cvss":3.1,"epss":0.0069,"slug":"cve-2022-25238-stored-xss-via-html-fields-in-silverstripe-framework","title":"Stored XSS via HTML fields in SilverStripe Framework","severity":"low","exploited":false,"published_at":"2022-06-29T22:14:03+00:00","url":"https://junglewise.ai/threats/cve-2022-25238-stored-xss-via-html-fields-in-silverstripe-framework"},{"cve":"CVE-2022-38724","cvss":3.1,"epss":0.0068,"slug":"cve-2022-38724-silverstripe-xss-in-shortcodes","title":"Silverstripe XSS in shortcodes","severity":"low","exploited":false,"published_at":"2022-11-21T23:58:20+00:00","url":"https://junglewise.ai/threats/cve-2022-38724-silverstripe-xss-in-shortcodes"},{"cve":"CVE-2020-9311","cvss":3.1,"epss":0.0056,"slug":"cve-2020-9311-silverstripe-cms-xss-vulnerability","title":"Silverstripe CMS XSS Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T17:23:42+00:00","url":"https://junglewise.ai/threats/cve-2020-9311-silverstripe-cms-xss-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}