Vulnerability Name CVE Severity
silverstripeCMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-12246) CVE-2019-12246
silverstripeCMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-12437) CVE-2019-12437
silverstripeCMS Cryptographic Issues Vulnerability (CVE-2010-5079) CVE-2010-5079
silverstripeCMS CVE-2019-12204 Vulnerability (CVE-2019-12204) CVE-2019-12204
silverstripeCMS CVE-2019-12617 Vulnerability (CVE-2019-12617) CVE-2019-12617
silverstripeCMS CVE-2019-16409 Vulnerability (CVE-2019-16409) CVE-2019-16409
silverstripeCMS CVE-2020-6164 Vulnerability (CVE-2020-6164) CVE-2020-6164
silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-4822) CVE-2010-4822
silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-5187) CVE-2010-5187
silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-5188) CVE-2010-5188
silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-6789) CVE-2013-6789
silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-12849) CVE-2017-12849
silverstripeCMS Files or Directories Accessible to External Parties Vulnerability (CVE-2019-14273) CVE-2019-14273
silverstripeCMS Improper Authentication Vulnerability (CVE-2020-26136) CVE-2020-26136
silverstripeCMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-5091) CVE-2010-5091
silverstripeCMS Improper Input Validation Vulnerability (CVE-2011-4962) CVE-2011-4962
silverstripeCMS Improper Input Validation Vulnerability (CVE-2013-2653) CVE-2013-2653
silverstripeCMS Improper Input Validation Vulnerability (CVE-2020-26138) CVE-2020-26138
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-1593) CVE-2010-1593
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4823) CVE-2010-4823
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-5095) CVE-2010-5095
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4958) CVE-2011-4958
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-0976) CVE-2012-0976
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4968) CVE-2012-4968
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-6458) CVE-2012-6458
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5063) CVE-2015-5063
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8606) CVE-2015-8606
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-5197) CVE-2017-5197
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-14498) CVE-2017-14498
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-12205) CVE-2019-12205
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14272) CVE-2019-14272
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-19325) CVE-2019-19325
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-9311) CVE-2020-9311
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36150) CVE-2021-36150
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28803) CVE-2022-28803
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37421) CVE-2022-37421
silverstripeCMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2017-18049) CVE-2017-18049
silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6753) CVE-2008-6753
silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-1433) CVE-2009-1433
silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4824) CVE-2010-4824
silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2011-4959) CVE-2011-4959
silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2011-4960) CVE-2011-4960
silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-5715) CVE-2019-5715
silverstripeCMS Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') Vulnerability (CVE-2021-41559) CVE-2021-41559
silverstripeCMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-25817) CVE-2020-25817
silverstripeCMS Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2019-19326) CVE-2019-19326
silverstripeCMS Incorrect Authorization Vulnerability (CVE-2021-28661) CVE-2021-28661
silverstripeCMS Incorrect Default Permissions Vulnerability (CVE-2020-6165) CVE-2020-6165
silverstripeCMS Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2019-12245) CVE-2019-12245
silverstripeCMS Other Vulnerability (CVE-2007-2321) CVE-2007-2321
silverstripeCMS Other Vulnerability (CVE-2015-5062) CVE-2015-5062
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5078) CVE-2010-5078
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5087) CVE-2010-5087
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5089) CVE-2010-5089
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5090) CVE-2010-5090
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5093) CVE-2010-5093
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5094) CVE-2010-5094
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4961) CVE-2011-4961
silverstripeCMS Session Fixation Vulnerability (CVE-2019-12203) CVE-2019-12203
silverstripeCMS Session Fixation Vulnerability (CVE-2022-24444) CVE-2022-24444
silverstripeCMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-9280) CVE-2020-9280
SimpleHelp Path Traversal (CVE-2024-57727) CVE-2024-57727 CVE-2024-57726 CVE-2024-57728
Sitecore Arbitrary File Read (CVE-2024-46938) CVE-2024-46938
Sitecore XM/XP Insecure Deserialization (CVE-2025-27218) CVE-2025-27218
Sitecore XP Deserialization RCE (CVE-2021-42237) CVE-2021-42237
Sitecore XP TemplateParser RCE (CVE-2023-35813) CVE-2023-35813
Skipper Incorrect Authorization Vulnerability (CVE-2022-34296) CVE-2022-34296
Skipper Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-38580) CVE-2022-38580
Skype for Business SSRF (CVE-2023-41763) CVE-2023-41763
Snoop Servlet information disclosure
SOAP WS-Addressing SSRF
SolarWinds Orion API Auth bypass (CVE-2020-10148) CVE-2020-10148
SolarWinds Serv-U Directory Traversal (CVE-2024-28995) CVE-2024-28995
SolarWinds Web Help Desk Hardcoded Credential (CVE-2024-28987) CVE-2024-28987
SolarWinds Web Help Desk RCE (CVE-2024-28986) CVE-2024-28986