Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-28803: Silverstripe CMS » the open source CMS that empowers great web teams

In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).

CVE
#xss#web#git#java#auth

This site requires you to update your browser. Your browsing experience maybe affected by not having the most up to date version.

What is SilverStripe?

******Super flexible & extensible**

Silverstripe CMS fits the outcomes you want, and doesn’t force your business outcomes into an out-of-the-box solution. Customise to your needs!

Easy-to-use

You can be the CMS expert in no time! Get started quickly and deliver your content to your users fast.

Robust & secure

Don’t stay awake at night worrying! Silverstripe CMS is solid as a rock, with enterprise-level security and support, so you can rest easy!

Open source

Collaboration from our global army of community members and commercially supported by Silverstripe.

Designed for digital teams

  • Developer
  • Marketer
  • Author
  • IT Manager

Easy to learn
Silverstripe Framework is created from the ground up to be easy to pick up and customise.

Optimised to produce highly reusable code
Silverstripe Framework promotes coding structure that is easy to read and maintain.

Powerful frontend template engine
Our templating engine is designed with frontend in mind. This makes creating digital experiences easy and fast.

Faster to market
Launch campaign pages straight from the CMS without the time-consuming development process.

Easy to test and refine
Empower you to quickly test and refine campaigns as you go.

Faster communications
Own the content and respond quickly to customers’ feedback.

Clear and easy-to-use
Silverstripe CMS is designed to be simple to learn and easy to use.

Grow with your needs
Whether updating a page or publishing multiple pages on a large scale site.

Permission controls
Give access to edit only specific areas of your site.

Secure and scalable
Architected to safeguard your data from malicious activity or data-loss, even while scaling up complex sites.

Supported at an enterprise-level
Behind the collaborative contributions of our open source community, Silverstripe CMS and Silverstripe Framework are backed by Silverstripe.

Robust and cost effective
Silverstripe CMS and Silverstripe Framework are built with reliability in mind. They are updated regularly and structured to be extendable.

Getting started

Sites powered by SilverStripe CMS

50,000+

Live SilverStripe sites

4,000+

Showcased SilverStripe sites

400+

Freelance developers and agencies

Latest news

Revising our approach to major release

We are publishing a Request For Comment (RFC) on a new Major Release Policy proposal. Our primary objective with this policy proposal is to provide certainty to Silverstripe CMS project owners by adopting a major release cadence that is sustainable and manageable. We are seeking feedback from the Silverstripe CMS community.

read

UnDigital® uses Silverstripe CMS to launch 3 sites at once for Thyme Lifestyle Resort

Digital experience agency, UnDigital, has been working with Thyme Lifestyle Resort, owned by Serenitas, to develop four websites using Silverstripe CMS with subsites. Throughout the build, both Serenitas and UnDigital have been excited by the usability of the CMS and the efficiencies the use of subsites has created for them both. This case study article discusses the brief Serenitas gave and the flawless websites UnDigital was able to deliver, using Silverstripe CMS.

read

Related news

GHSA-rppc-655v-7j3c: Stored XSS in link tags added via XHR in SilverStripe Framework

SilverStripe Framework 4.x prior to 4.10.9 is vulnerable to cross-site scripting inside the href attribute of an HTML hyperlink, which can be added to website content via XMLHttpRequest (XHR) by an authenticated CMS user.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907