Summary
silverstripe/versioned has XSS in archive admin restore
Advisory details
Impact
It's possible to use the page title as an XSS vector when restoring a page in ArchiveAdmin
Reporter
Steve Boyd Silverstripe Ltd.
References
- https://github.com/advisories/GHSA-m4g4-86qc-v8w7
- https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7
- https://github.com/silverstripe/silverstripe-versioned/pull/541
- https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/versioned/CVE-2026-55779.yaml
- https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1
- https://www.silverstripe.org/download/security-releases/cve-2026-55779
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-63670
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
- MEDIUMCVE-2026-73295
Material for MkDocs: DOM XSS in search suggestions via query parameter
- HIGHGHSA-99rq-75j6-5j9f
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
- MEDIUMCVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
- MEDIUMCVE-2026-82396
Sulu: Stored XSS via media download inline-disposition override
- MEDIUMGHSA-cp6q-959q-f8rh
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes