Cross-Site Scripting in Silverstripe Versioned by Silverstripe
CVE-2026-55779
5.4MEDIUM
What is CVE-2026-55779?
A cross-site scripting vulnerability exists in the Silverstripe Versioned component, which manages versioning for Silverstripe models. Prior to version 3.2.1, the RestoreAction::getRestoreMessage() function fails to sanitize user-controlled data such as titles or URL segments. This flaw can be exploited when an administrator restores an archived page containing malicious input, potentially resulting in the execution of injected JavaScript within the admin's browser session. This may compromise the confidentiality and integrity of the CMS, making it critical for users to upgrade to the patched version 3.2.1 to ensure their security.
Affected Version(s)
silverstripe-versioned < 3.2.1
