silverstripe/graphql
GraphQL server for SilverStripe models and other data
Activity
- Latest release
- 5mo ago
- Total releases
- 117
- Cadence
- ~6 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Jan 17, 2017
| Version | Released | |
|---|---|---|
6.1.1
patch
| ||
5.3.2
patch
| ||
6.1.0
minor
| ||
6.0.0
major
| ||
5.3.1
patch
| ||
5.3.0
minor
| ||
6.0.0-beta1
pre
| ||
5.3.0-rc1
pre
| ||
5.2.4
patch
| ||
6.0.0-alpha1
pre
| ||
5.2.3
patch
| ||
5.2.2
patch
| ||
5.2.1
patch
| ||
4.3.8
patch
| ||
5.2.0
minor
| ||
5.1.3
patch
| ||
4.3.7
patch
| ||
5.1.2
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.3.6
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.1
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.3.5
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0
minor
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
5.0.3
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.3.4
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.2.5
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.1.3
patch
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.8.2
patch
| ||
5.1.0-rc1
pre
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
5.0.2
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.3
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.1
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.2
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.1
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0
major
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0-rc1
pre
| ||
4.3.0
minor
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.2.4
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.0-rc1
pre
1 CVE
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.2.3
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.2
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.2.2
patch
3 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-28104
GHSA-67g8-c724-8mp3
Mar 16, 2023
DDOS attack on graphql endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An attacker could use a specially crafted graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed and particularly large/complex graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this will likely further mitigate the risk. Upgrade to Affected versions
4.1.1
4.2.2
Fixed in
4.1.2
4.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.1
patch
3 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-28104
GHSA-67g8-c724-8mp3
Mar 16, 2023
DDOS attack on graphql endpoints
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An attacker could use a specially crafted graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed and particularly large/complex graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this will likely further mitigate the risk. Upgrade to Affected versions
4.1.1
4.2.2
Fixed in
4.1.2
4.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.2.1
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0-beta2
pre
| ||
5.0.0-beta1
pre
| ||
4.2.0
minor
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0
minor
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.0.2
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.0.1
patch
2 CVEs
CVE-2023-44401
GHSA-jgph-w8rh-xf5p
Jan 23, 2024
View permissions are bypassed for paginated lists of ORM data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed by ensuring no new records are pulled in from the database after performing This behaviour is consistent with how pagination works in other areas of Silverstripe CMS, such as in You can choose to disable these permission checks by disabling the Note that this vulnerability does not affect version 3.x. Base CVSS: 5.3 Reported by: Eduard Briem from Hothouse Creative, Nelson Referenceshttps://www.silverstripe.org/download/security-releases/CVE-2023-44401 Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
+ 20 more Show less
4.2.3
4.2.4
4.2.5
4.3.0
4.3.0-rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
Fixed in
4.3.7
5.1.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-40180
GHSA-v23w-pppm-jh66
Oct 17, 2023
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. The fix includes some new configuration options which you might want to tweak for your project, based on your own requirements. See the documentation in the references for details. PatchesPatched in 3.8.2, 4.1.3, 4.2.5, 4.3.4, 5.0.3 References
Reported byJason Nguyen from phew (https://phew.co.nz/) Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0-rc1
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
+ 50 more Show less
3.2.0
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.0-beta1
3.3.0-rc1
3.4.0
3.4.0-beta1
3.4.0-rc1
3.4.1
3.5.0
3.5.0-beta1
3.5.0-rc1
3.5.1
3.5.2
3.6.0
3.6.0-alpha1
3.6.0-alpha2
3.6.0-beta1
3.6.0-rc1
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
4.0.0
4.0.1
4.0.2
4.1.0
4.1.0-beta1
4.1.0-rc1
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
5.0.0
5.0.1
5.0.2
Fixed in
3.8.2
4.1.3
4.2.5
4.3.4
5.0.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0-alpha1
pre
|