GHSA-g8wr-r2v2-vqc6HighCVSS 8.8

silverstripe/userforms vulnerable to remote code execution via userforms email subject

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.

Reported by

Jack Wallace from Bastion Security

🎯 Affected products3

  • composer/silverstripe/userforms:< 6.4.9
  • composer/silverstripe/userforms:>= 7.0.0, < 7.0.7
  • composer/silverstripe/userforms:>= 7.1.0, < 7.1.1

🔗 References (11)