Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jack Wallace

Researcher fromBastion Security
#23295of 56,330
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-54846
5.4
2026-07-01
Silverstripe · Silverstripe/Framework · CVE-2026-54720
**Name of the Vulnerable Software and Affected Versions** Silverstripe Framework versions prior to 6.2.2 **Description** The "Insert media from web" functionality in the CMS is susceptible to Cross-Site Scripting (XSS), a technique where malicious scripts are injected into trusted websites, when processing a specially crafted embed. **Recommendations** Update to version 6.2.2.
PT-2024-25029
5.4
2024-07-17
Silverstripe · Silverstripe/Framework · CVE-2024-32981
**Name of the Vulnerable Software and Affected Versions** Silverstripe framework versions prior to 5.2.16 **Description** A bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitised on the client-side, but server-side sanitisation doesn't catch it. **Recommendations** For versions prior to 5.2.16, upgrade to version 5.2.16 or later to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.