Remote Code Execution Vulnerability in Silverstripe UserForms
CVE-2026-54721
What is CVE-2026-54721?
The Silverstripe UserForms extension for the Silverstripe CMS is vulnerable to a remote code execution (RCE) flaw due to improper handling of the email recipient subject field. Users with authenticated access to the CMS and permission to alter configurations can input malicious payloads that are processed as executable server-side code. This flaw can lead to significant risks, allowing unauthorized scripts to run on the server, leading to potential data breaches and service disruptions. The issue has been rectified in the latest releases, and users are strongly advised to update to versions 6.4.9, 7.0.7, or 7.1.1 to safeguard their installations.
Affected Version(s)
silverstripe-userforms < 6.4.9 < 6.4.9
silverstripe-userforms >= 7.0.0, < 7.0.7 < 7.0.0, 7.0.7
silverstripe-userforms >= 7.1.0, < 7.1.1 < 7.1.0, 7.1.1
