Silverstripe is a modestly represented content-management and web-application framework whose vulnerability footprint, despite a narrow product list, sits deep in web-publishing deployments and spans features from core framework components to GraphQL, asset handling, and admin interfaces. The recurring weakness classes center on application-layer input handling and state management, including cross-site scripting, SQL injection, CSRF, and exposure of sensitive information, which are characteristic of server-side web platforms where user input flows across multiple processing stages. A meaningful share of the vendor's disclosures reach serious severity, and public exploit code and confirmed in-the-wild exploitation do occur for this class of web-framework vulnerability, though neither dominates the profile. Defenders should integrate Silverstripe framework updates into their patch cycles for all publishing properties running the platform and apply defense-in-depth for request validation and output encoding; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Silverstripe over time
Signals from CVEs in this vendor scope (89 CVEs).
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12149CRITICAL SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 | Jun 11, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-5715CRITICAL All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and | Apr 11, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-12204CRITICAL In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access. | Sep 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-9309HIGH Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these f | Jul 15, 2020 | 8.8 | 28 | NO | NO |
CVE-2022-38148HIGH Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | Nov 21, 2022 | 8.8 | 27 | NO | NO |
CVE-2011-4958MEDIUM Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary we | Apr 8, 2014 | 4.3 | 26 | NO | YES |
CVE-2022-42949HIGH Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. | Dec 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-6164HIGH In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silve | Jul 15, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-12437HIGH In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations, | Feb 19, 2020 | 8.8 | 25 | NO | NO |
CVE-2013-2653MEDIUM security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by t | Nov 13, 2013 | 5.8 | 25 | NO | YES |
Signals from CVEs in this vendor scope (89 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Silverstripe.
Media articles that mention a CVE ID that affects a product developed by Silverstripe — matched by CVE ID, not by vendor name.