← Terug naar overzicht

A server-side code injection vulnerability exists in Silverstripe UserForms versions 6.0.0 through 6.4.8, 7.0.0 through 7.0.6, and 7.1.0. The email recipient subject field in the CMS accepts specially crafted payloads that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure UserForms email recipients can exploit this to run arbitrary code on the server. The vulnerability compromises confidentiality, integrity, and availability of the affected system. Patches have been released in versions 6.4.9, 7.0.7, and 7.1.1. Users are strongly advised to upgrade to the fixed versions immediately.

Affected products

  • Silverstripe CMS
  • Silverstripe UserForms 6.0.0-6.4.8
  • Silverstripe UserForms 7.0.0-7.0.6
  • Silverstripe UserForms 7.1.0

Related CVE's

  • CVE-2026-54721

Categories

  • Enterprise Applications
  • Web Technologies