Remote Code Execution Vulnerability in Silverstripe UserForms
CVE-2026-54721

8.8HIGH

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-54721?

The Silverstripe UserForms extension for the Silverstripe CMS is vulnerable to a remote code execution (RCE) flaw due to improper handling of the email recipient subject field. Users with authenticated access to the CMS and permission to alter configurations can input malicious payloads that are processed as executable server-side code. This flaw can lead to significant risks, allowing unauthorized scripts to run on the server, leading to potential data breaches and service disruptions. The issue has been rectified in the latest releases, and users are strongly advised to update to versions 6.4.9, 7.0.7, or 7.1.1 to safeguard their installations.

Affected Version(s)

silverstripe-userforms < 6.4.9 < 6.4.9

silverstripe-userforms >= 7.0.0, < 7.0.7 < 7.0.0, 7.0.7

silverstripe-userforms >= 7.1.0, < 7.1.1 < 7.1.0, 7.1.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.