CVE-2026-54721
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email
CVSS
8.8
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 27 ago 2026 · Última mod.: 27 ago 2026 · CWE-94
Sin historial EPSS suficiente todavía.
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code on the server, compromising confidentiality, integrity, and availability. This issue is fixed in versions 6.4.9, 7.0.7, and 7.1.1.
- github.comhttps://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702
- github.comhttps://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c
- github.comhttps://github.com/silverstripe/silverstripe-userforms/pull/1441
- github.comhttps://github.com/silverstripe/silverstripe-userforms/pull/1442
- github.comhttps://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9
- github.comhttps://github.com/silverstripe/silverstripe-userforms/releases/tag/7.0.7
- github.comhttps://github.com/silverstripe/silverstripe-userforms/releases/tag/7.1.1
- github.comhttps://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6