{"id":"CVE-2026-54717","title":"Silverstripe CMS is an open source content management system","summary":"Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb t…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"silverstripe","product":"silverstripe/cms","affected":["silverstripe/cms < 6.2.1"],"patched":["silverstripe/cms 6.2.1"],"published":"2026-08-06","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:51:43.490","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54717","references":[{"url":"https://github.com/silverstripe/silverstripe-cms/commit/62f9912baa18c80304f3fa8b6eca71bb5dc2d21e","label":"security-advisories@github.com"},{"url":"https://github.com/silverstripe/silverstripe-cms/pull/3175","label":"security-advisories@github.com"},{"url":"https://github.com/silverstripe/silverstripe-cms/releases/tag/6.2.1","label":"security-advisories@github.com"},{"url":"https://github.com/silverstripe/silverstripe-cms/security/advisories/GHSA-w3cp-g2pf-65wh","label":"security-advisories@github.com"},{"url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/cms/CVE-2026-54717.yaml"},{"url":"https://www.silverstripe.org/download/security-releases/cve-2026-54717"},{"url":"https://github.com/advisories/GHSA-w3cp-g2pf-65wh"}],"tags":["nvd","ghsa","composer"],"epss":0.0024,"epssPercentile":0.15421,"aliases":["GHSA-w3cp-g2pf-65wh"],"ecosystem":"composer","ingestedAt":"2026-08-06T21:04:22.296Z","slug":"CVE-2026-54717","body":"## Overview\n\nSilverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54717)\n\nAffected packages:\n\n- `silverstripe/cms < 6.2.1`\n\nPatched in:\n\n- `silverstripe/cms 6.2.1`\n\nSource: https://github.com/advisories/GHSA-w3cp-g2pf-65wh","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}