GHSA-m4g4-86qc-v8w7MediumCVSS 5.4
silverstripe/versioned has XSS in archive admin restore
🔗 CVE IDs covered (1)
📋 Description
Impact
It's possible to use the page title as an XSS vector when restoring a page in ArchiveAdmin
Reporter
Steve Boyd Silverstripe Ltd.
🎯 Affected products1
- composer/silverstripe/versioned:< 3.2.1
🔗 References (7)
- https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7
- https://github.com/silverstripe/silverstripe-versioned/pull/541
- https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/versioned/CVE-2026-55779.yaml
- https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1
- https://www.silverstripe.org/download/security-releases/cve-2026-55779
- https://github.com/advisories/GHSA-m4g4-86qc-v8w7