StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
MEDIUMSupply chain

CVE-2026-54720

Packagist · silverstripe/framework

Summary

Silverstripe Framework: Possible XSS attack through media embed

Advisory details

Impact

The "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed.

Reported by

Jack Wallace from Bastion Security

References

  • https://github.com/advisories/GHSA-gvrw-qqp5-jgc5
  • https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-gvrw-qqp5-jgc5
  • https://nvd.nist.gov/vuln/detail/CVE-2026-54720
  • https://github.com/silverstripe/silverstripe-framework/pull/11993
  • https://github.com/silverstripe/silverstripe-framework/commit/1bcb02adfc365c6436dc26ab2f6dd32d97f3979b
  • https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2026-54720.yaml
  • https://github.com/silverstripe/silverstripe-framework/releases/tag/6.2.2
  • https://www.silverstripe.org/download/security-releases/cve-2026-54720
SourceStateward
Severitymedium
CVSS5.4
EPSS0.3% (p18)
Also known asGHSA-gvrw-qqp5-jgc5
CWECWE-79
Added2026-08-27

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • MEDIUMCVE-2026-63670

    ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close

  • MEDIUMCVE-2026-73295

    Material for MkDocs: DOM XSS in search suggestions via query parameter

  • HIGHGHSA-99rq-75j6-5j9f

    SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

  • MEDIUMCVE-2026-68921

    DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)

  • MEDIUMCVE-2026-82396

    Sulu: Stored XSS via media download inline-disposition override

  • MEDIUMGHSA-cp6q-959q-f8rh

    Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture