Vulnerabilities (CVE)

Filtered by vendor Silverstripe Subscribe
Filtered by product Framework
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25238 1 Silverstripe 1 Framework 2022-07-08 3.5 LOW 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.