CVE-2026-54717Medium· 5.4▾ SunlitSilverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
silverstripe/cms < 6.2.1Patched in:
silverstripe/cms 6.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55779Medium· 5.4Silverstripe Versioned provides versioning for Silverstripe models
CVE-2026-54720Medium· 5.4Silverstripe Framework: Possible XSS attack through media embed
CVE-2026-54721High· 8.8Silverstripe UserForms provides a visual form builder for the Silverstripe CMS
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41183Medium· 6.5jQuery-UI is the official jQuery user interface library