PT-2026-82687 · Silverstripe · Userforms

CVE-2026-54721

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Silverstripe UserForms versions prior to 6.4.9 Silverstripe UserForms versions prior to 7.0.7 Silverstripe UserForms versions prior to 7.1.1
Description An authenticated CMS user with permissions to configure a UserForms email recipient can execute arbitrary server-side code. This occurs because the email recipient subject field in the CMS accepts specially crafted payloads that the server interprets as executable code, potentially compromising confidentiality, integrity, and availability.
Recommendations Update to version 6.4.9. Update to version 7.0.7. Update to version 7.1.1.

Exploit

Fix

Code Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54721
GHSA-G8WR-R2V2-VQC6

Affected Products

Userforms