Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.

Project Subscriptions

Vendors Products
Silverstripe Subscribe
Silverstripe Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w3cp-g2pf-65wh Silverstripe: XSS in breadcrumbs in page list view
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Silverstripe
Silverstripe silverstripe
Vendors & Products Silverstripe
Silverstripe silverstripe

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.
Title Silverstripe: XSS in breadcrumbs in page list view
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-07T14:32:58.836Z

Reserved: 2026-06-15T23:07:33.231Z

Link: CVE-2026-54717

cve-icon Vulnrichment

Updated: 2026-08-07T14:32:54.451Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:00:05Z

Weaknesses