Cross-Site Scripting in Silverstripe Versioned by Silverstripe
CVE-2026-55779

5.4MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55779?

A cross-site scripting vulnerability exists in the Silverstripe Versioned component, which manages versioning for Silverstripe models. Prior to version 3.2.1, the RestoreAction::getRestoreMessage() function fails to sanitize user-controlled data such as titles or URL segments. This flaw can be exploited when an administrator restores an archived page containing malicious input, potentially resulting in the execution of injected JavaScript within the admin's browser session. This may compromise the confidentiality and integrity of the CMS, making it critical for users to upgrade to the patched version 3.2.1 to ensure their security.

Affected Version(s)

silverstripe-versioned < 3.2.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.