dnadesign/silverstripe-elemental
Create pages in Silverstripe CMS using content blocks
Activity
- Latest release
- 3w ago
- Total releases
- 150
- Cadence
- ~8 days
- Last 12 months
- 19
Reach
- Stars
- 110
Details
- License
- BSD-3-Clause
- First release
- Jun 04, 2015
| Version | Released | |
|---|---|---|
6.2.3
patch
|
6.2.3
patch
Dependencies (6)
Changelog
Compare changes
|
|
6.2.2
patch
|
6.2.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
6.2.1
patch
|
6.2.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
6.2.0
minor
| ||
6.2.0-beta1
pre
| ||
6.1.6
patch
| ||
5.4.10
patch
|
5.4.10
patch
Dependencies (8)
Changelog
Compare changes
|
|
6.1.5
patch
| ||
5.4.9
patch
| ||
6.1.4
patch
| ||
5.4.8
patch
| ||
6.1.3
patch
| ||
5.4.7
patch
| ||
6.1.2
patch
| ||
5.4.6
patch
| ||
6.1.1
patch
| ||
6.1.0
minor
| ||
6.0.4
patch
| ||
5.4.5
patch
| ||
6.1.0-rc1
pre
| ||
6.1.0-beta1
pre
| ||
6.0.3
patch
| ||
6.0.2
patch
| ||
5.4.4
patch
| ||
6.0.1
patch
| ||
5.4.3
patch
| ||
6.0.0
major
| ||
6.0.0-rc1
pre
| ||
5.4.2
patch
|
5.4.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.4.1
patch
| ||
5.4.0
minor
| ||
5.3.12
patch
|
5.3.12
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.3.11
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.10
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
6.0.0-beta1
pre
| ||
5.4.0-rc1
pre
| ||
5.3.9
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.4.0-beta1
pre
| ||
5.3.8
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.7
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.6
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.5
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.4
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev |
5.3.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.3.3
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
6.0.0-alpha1
pre
|
6.0.0-alpha1
pre
Dependencies (7)
Changelog
Compare changes
|
|
5.3.2
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.1
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.3.0
minor
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.2.4
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
5.2.3
patch
1 CVE
CVE-2025-25197
GHSA-x8xm-c7p8-2pj2
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. References
Affected versions
2.1.2
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
+ 96 more Show less
3.1.3
4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
Fixed in
5.3.12
References
Updated Apr 10, 2025 · Source: OSV.dev |
5.2.3
patch
Dependencies (8)
Changelog
Compare changes
|