A server-side code injection vulnerability exists in Silverstripe UserForms versions 6.0.0 through 6.4.8, 7.0.0 through 7.0.6, and 7.1.0. The email recipient subject field in the CMS accepts specially crafted payloads that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure UserForms email recipients can exploit this to run arbitrary code on the server. The vulnerability compromises confidentiality, integrity, and availability of the affected system. Patches have been released in versions 6.4.9, 7.0.7, and 7.1.1. Users are strongly advised to upgrade to the fixed versions immediately.