GHSA-gvrw-qqp5-jgc5MediumCVSS 5.4

Silverstripe Framework: Possible XSS attack through media embed

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed.

Reported by

Jack Wallace from Bastion Security

🎯 Affected products1

  • composer/silverstripe/framework:< 6.2.2

🔗 References (8)