Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g8wr-r2v2-vqc6 | silverstripe/userforms vulnerable to remote code execution via userforms email subject |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code on the server, compromising confidentiality, integrity, and availability. This issue is fixed in versions 6.4.9, 7.0.7, and 7.1.1. | |
| Title | Silverstripe UserForms: Remote code execution via userforms email subject | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T16:52:46.023Z
Reserved: 2026-06-15T23:07:33.231Z
Link: CVE-2026-54721
No data.
Status : Received
Published: 2026-08-27T20:17:49.973
Modified: 2026-08-27T20:17:49.973
Link: CVE-2026-54721
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
Github GHSA