silverstripe/userforms
UserForms module provides a visual form builder for the Silverstripe CMS. No coding required to build forms such as contact pages.
Activity
- Latest release
- 3w ago
- Total releases
- 179
- Cadence
- ~11 days
- Last 12 months
- 14
Reach
- Stars
- 132
Details
- License
- BSD-3-Clause
- First release
- Jul 18, 2013
| Version | Released | |
|---|---|---|
7.1.3
patch
|
7.1.3
patch
Dependencies (7)
Changelog
Compare changes
|
|
7.1.2
patch
|
7.1.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
7.1.1
patch
|
7.1.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
6.4.9
patch
| ||
7.0.7
patch
|
7.0.7
patch
Dependencies (7)
Changelog
Compare changes
|
|
7.1.0
minor
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.1.0-beta1
pre
| ||
7.0.6
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.5
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.8
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.7
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.4
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.3
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.6
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.2
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.1
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.5
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.4
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.0
major
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.0-rc1
pre
| ||
6.4.3
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.2
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.1
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.0
minor
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.0-beta1
pre
| ||
6.4.0-rc1
pre
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.4.0-beta1
pre
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.3.2
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.3.1
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
7.0.0-alpha1
pre
| ||
6.3.0
minor
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.10
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.3.0-rc1
pre
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.9
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.8
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.7
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
5.15.11
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.6
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.5
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.4
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.3
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.2
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.1
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.0
minor
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.2.0-rc1
pre
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.1.2
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
5.15.10
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.1.1
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
5.15.9
patch
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev | ||
6.1.0
minor
1 CVE
CVE-2026-54721
GHSA-g8wr-r2v2-vqc6
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server. Reported byJack Wallace from Bastion Security Affected versions
0.5.1
1.0.1
1.1.0-beta
2.0.1
2.0.1-rc1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
+ 168 more Show less
2.0.8
2.0.9
3.0.0
3.0.0-beta1
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0
5.13.0-beta1
5.13.0-rc1
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0
5.14.0-beta1
5.14.0-rc1
5.14.1
5.14.2
5.14.3
5.15.0
5.15.0-beta1
5.15.0-rc1
5.15.1
5.15.10
5.15.11
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
5.6.0-rc1
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.0-beta1
5.9.0-rc1
5.9.1
6.0.0
6.0.0-beta1
6.0.0-rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.0-beta1
6.1.0-rc1
6.1.1
6.1.2
6.2.0
6.2.0-beta1
6.2.0-rc1
6.2.1
6.2.10
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.3.0
6.3.0-beta1
6.3.0-rc1
6.3.1
6.3.2
6.4.0
6.4.0-beta1
6.4.0-rc1
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8
v5.9.2
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
Fixed in
6.4.9
7.0.7
7.1.1
References
Updated Aug 27, 2026 · Source: OSV.dev |