StatewardStateward
PlateformeTarifsConformitéVulnérabilitésÉtudes de casDocsBlogÀ propos
enfr
Démo / ContactCommencer gratuitement
← Toutes les vulnérabilités
MEDIUMSupply chain

CVE-2026-54720

Packagist · silverstripe/framework

Résumé

Silverstripe Framework: Possible XSS attack through media embed

Détails de l’avis

Impact

The "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed.

Reported by

Jack Wallace from Bastion Security

Références

  • https://github.com/advisories/GHSA-gvrw-qqp5-jgc5
  • https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-gvrw-qqp5-jgc5
  • https://nvd.nist.gov/vuln/detail/CVE-2026-54720
  • https://github.com/silverstripe/silverstripe-framework/pull/11993
  • https://github.com/silverstripe/silverstripe-framework/commit/1bcb02adfc365c6436dc26ab2f6dd32d97f3979b
  • https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2026-54720.yaml
  • https://github.com/silverstripe/silverstripe-framework/releases/tag/6.2.2
  • https://www.silverstripe.org/download/security-releases/cve-2026-54720
SourceStateward
Severitymedium
CVSS5.4
EPSS0.3% (p18)
Also known asGHSA-gvrw-qqp5-jgc5
CWECWE-79
Added2026-08-27

Votre projet est-il exposé ? Stateward vérifie chaque dépendance à chaque pull request, et ne la signale que si votre code l’atteint réellement.

Vérifier mon dépôt
Résumer avec
ChatGPTClaudePerplexity

Vulnérabilités liées

Tout Supply chain →
  • MEDIUMCVE-2026-63670

    ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close

  • MEDIUMCVE-2026-73295

    Material for MkDocs: DOM XSS in search suggestions via query parameter

  • HIGHGHSA-99rq-75j6-5j9f

    SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

  • MEDIUMCVE-2026-68921

    DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)

  • MEDIUMCVE-2026-82396

    Sulu: Stored XSS via media download inline-disposition override

  • MEDIUMGHSA-cp6q-959q-f8rh

    Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

StatewardStateward

Cybersécurité autonome pour tout votre code.

Une initiative de Yggdrasil Digital.

Produit

  • Plateforme
  • Ce que nous détectons
  • Comment nous protégeons
  • Tarifs
  • Conformité
  • Vulnérabilités
  • Blog
  • Commencer gratuitement

Ressources

  • Analyses d’incidents
  • Failles de fusion
  • Docs
  • Exemple concret
  • Glossaire
  • Comparatifs
  • API du flux ↗

Société

  • À propos
  • Yggdrasil Digital ↗

Légal

  • Mentions légales
  • CGU
  • CGV
  • Confidentialité
  • Cookies
  • DPA

Suivre

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Flux de menaces (RSS) ↗
  • hello@stateward.com

Stateward fournit une analyse de sécurité automatisée et ne garantit pas la détection de toutes les vulnérabilités. Il est conçu pour appuyer, et non remplacer, de bonnes pratiques de sécurité et le jugement humain.

© 2026 Stateward. Tous droits réservés.Une initiative Yggdrasil Digital