Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "4.11.13"
},
{
"introduced": "3.0.0"
},
{
"last_affected": "3.7.7"
}
]
}