StatewardStateward
PlateformeTarifsConformitéVulnérabilitésÉtudes de casDocsBlogÀ propos
enfr
Démo / ContactCommencer gratuitement
← Toutes les vulnérabilités
HIGHSupply chain

CVE-2026-54721

Packagist · silverstripe/userforms

Résumé

silverstripe/userforms vulnerable to remote code execution via userforms email subject

Détails de l’avis

Impact

The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.

Reported by

Jack Wallace from Bastion Security

Références

  • https://github.com/advisories/GHSA-g8wr-r2v2-vqc6
  • https://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6
  • https://github.com/silverstripe/silverstripe-userforms/pull/1441
  • https://github.com/silverstripe/silverstripe-userforms/pull/1442
  • https://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702
  • https://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c
  • https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yaml
  • https://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9
SourceStateward
Severityhigh
CVSS8.8
EPSS0.4% (p35)
Also known asGHSA-g8wr-r2v2-vqc6
CWECWE-20, CWE-94
Added2026-08-27

Votre projet est-il exposé ? Stateward vérifie chaque dépendance à chaque pull request, et ne la signale que si votre code l’atteint réellement.

Vérifier mon dépôt
Résumer avec
ChatGPTClaudePerplexity

Vulnérabilités liées

Tout Supply chain →
  • CRITICALCVE-2026-54133

    jmespath.php has CompilerRuntime code injection via unescaped function names

  • HIGHCVE-2026-75911

    CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

  • HIGHCVE-2026-75858

    CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

  • CRITICALCVE-2026-62681

    Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

  • CRITICALCVE-2026-62682

    Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

  • CRITICALCVE-2026-72717

    Orval: Import-time RCE via schema default -> zod module-level template literal

StatewardStateward

Cybersécurité autonome pour tout votre code.

Une initiative de Yggdrasil Digital.

Produit

  • Plateforme
  • Ce que nous détectons
  • Comment nous protégeons
  • Tarifs
  • Conformité
  • Vulnérabilités
  • Blog
  • Commencer gratuitement

Ressources

  • Analyses d’incidents
  • Failles de fusion
  • Docs
  • Exemple concret
  • Glossaire
  • Comparatifs
  • API du flux ↗

Société

  • À propos
  • Yggdrasil Digital ↗

Légal

  • Mentions légales
  • CGU
  • CGV
  • Confidentialité
  • Cookies
  • DPA

Suivre

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Flux de menaces (RSS) ↗
  • hello@stateward.com

Stateward fournit une analyse de sécurité automatisée et ne garantit pas la détection de toutes les vulnérabilités. Il est conçu pour appuyer, et non remplacer, de bonnes pratiques de sécurité et le jugement humain.

© 2026 Stateward. Tous droits réservés.Une initiative Yggdrasil Digital