StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
MEDIUMSupply chain

CVE-2026-54717

Packagist · silverstripe/cms

Summary

Silverstripe: XSS in breadcrumbs in page list view

Advisory details

Impact

Page breadcrumbs in the CMS are vulnerable to XSS when viewed using the page list view

Reporter

Fase Rais Baradika

References

  • https://github.com/advisories/GHSA-w3cp-g2pf-65wh
  • https://github.com/silverstripe/silverstripe-cms/security/advisories/GHSA-w3cp-g2pf-65wh
  • https://github.com/silverstripe/silverstripe-cms/pull/3175
  • https://github.com/silverstripe/silverstripe-cms/commit/62f9912baa18c80304f3fa8b6eca71bb5dc2d21e
  • https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/cms/CVE-2026-54717.yaml
  • https://github.com/silverstripe/silverstripe-cms/releases/tag/6.2.1
  • https://www.silverstripe.org/download/security-releases/cve-2026-54717
SourceStateward
Severitymedium
CVSS5.4
EPSS0.2% (p15)
Also known asGHSA-w3cp-g2pf-65wh
CWECWE-79
Added2026-08-06

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • MEDIUMCVE-2026-63670

    ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close

  • MEDIUMCVE-2026-73295

    Material for MkDocs: DOM XSS in search suggestions via query parameter

  • HIGHGHSA-99rq-75j6-5j9f

    SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

  • MEDIUMCVE-2026-68921

    DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)

  • MEDIUMCVE-2026-82396

    Sulu: Stored XSS via media download inline-disposition override

  • MEDIUMGHSA-cp6q-959q-f8rh

    Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture