GHSA-g8wr-r2v2-vqc6HighCVSS 8.8
silverstripe/userforms vulnerable to remote code execution via userforms email subject
🔗 CVE IDs covered (1)
📋 Description
Impact
The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.
Reported by
Jack Wallace from Bastion Security
🎯 Affected products3
- composer/silverstripe/userforms:< 6.4.9
- composer/silverstripe/userforms:>= 7.0.0, < 7.0.7
- composer/silverstripe/userforms:>= 7.1.0, < 7.1.1
🔗 References (11)
- https://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6
- https://github.com/silverstripe/silverstripe-userforms/pull/1441
- https://github.com/silverstripe/silverstripe-userforms/pull/1442
- https://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702
- https://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yaml
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/7.0.7
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/7.1.1
- https://www.silverstripe.org/download/security-releases/cve-2026-54721
- https://github.com/advisories/GHSA-g8wr-r2v2-vqc6