silverstripe/userforms
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting silverstripe/userformspage 1 of 1
- CVE-2020-9280HIGHCVSS 7.5EG 7.5✓ Fixed in 5.4.22020-04-15
vulnerable: 5.0.0 ... 5.4.1 (14 versions)
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional sil…
- CVE-2026-54721HIGHCVSS 8.8EG 8.8✓ Fixed in 6.4.92026-08-27
vulnerable: 0.5.1 ... v5.9.2 (172 versions)
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as …
Check whether silverstripe/userforms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for silverstripe/userforms CVEs against the assets you own.
Start Free Scan →