StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
HIGHSupply chain

CVE-2026-54721

Packagist · silverstripe/userforms

Summary

silverstripe/userforms vulnerable to remote code execution via userforms email subject

Advisory details

Impact

The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.

Reported by

Jack Wallace from Bastion Security

References

  • https://github.com/advisories/GHSA-g8wr-r2v2-vqc6
  • https://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6
  • https://github.com/silverstripe/silverstripe-userforms/pull/1441
  • https://github.com/silverstripe/silverstripe-userforms/pull/1442
  • https://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702
  • https://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c
  • https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yaml
  • https://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9
SourceStateward
Severityhigh
CVSS8.8
EPSS0.4% (p35)
Also known asGHSA-g8wr-r2v2-vqc6
CWECWE-20, CWE-94
Added2026-08-27

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • CRITICALCVE-2026-54133

    jmespath.php has CompilerRuntime code injection via unescaped function names

  • HIGHCVE-2026-75911

    CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

  • HIGHCVE-2026-75858

    CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

  • CRITICALCVE-2026-62681

    Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

  • CRITICALCVE-2026-62682

    Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

  • CRITICALCVE-2026-72717

    Orval: Import-time RCE via schema default -> zod module-level template literal

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture