PT-2026-68756 · Silverstripe · Silverstripe Cms

CVE-2026-54717

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverstripe CMS versions prior to 6.2.1
Description Page breadcrumbs in the CMS are susceptible to cross-site scripting (XSS) when accessed via the page list view. This occurs because page titles are rendered into the breadcrumb trail without proper escaping, allowing malicious scripts to be executed in the browser.
Recommendations Update to version 6.2.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54717
GHSA-W3CP-G2PF-65WH

Affected Products

Silverstripe Cms