Skip to content

Commit 1ea1d5b

Browse files
committed
Silverstripe vulnerabilities April 2025
1 parent 1fefb5c commit 1ea1d5b

File tree

3 files changed

+24
-0
lines changed

3 files changed

+24
-0
lines changed
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
title: "CVE-2025-25197 - XSS attack in elemental \"Content blocks in use\" report"
2+
link: https://www.silverstripe.org/download/security-releases/cve-2025-25197
3+
cve: CVE-2025-25197
4+
branches:
5+
5.3.x:
6+
time: 2025-10-04 02:37:11
7+
versions: ['<5.3.12']
8+
reference: composer://dnadesign/silverstripe-elemental
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
title: "CVE-2025-30148 - XSS vulnerability in HTML editor"
2+
link: https://www.silverstripe.org/download/security-releases/cve-2025-30148
3+
cve: CVE-2025-30148
4+
branches:
5+
5.3.x:
6+
time: 2025-10-04 02:37:11
7+
versions: ['<5.3.23']
8+
reference: composer://silverstripe/framework
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
title: "SS-2025-001 - User enumeration via timing attack"
2+
link: https://www.silverstripe.org/download/security-releases/ss-2025-001
3+
cve: ~
4+
branches:
5+
5.3.x:
6+
time: 2025-10-04 02:37:11
7+
versions: ['<5.3.23']
8+
reference: composer://silverstripe/framework

0 commit comments

Comments
 (0)