GHSA-g8wr-r2v2-vqc6

Suggest an improvement
Source
https://github.com/advisories/GHSA-g8wr-r2v2-vqc6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-g8wr-r2v2-vqc6/GHSA-g8wr-r2v2-vqc6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g8wr-r2v2-vqc6
Aliases
Published
2026-08-27T16:53:17Z
Modified
2026-08-27T17:10:36Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
silverstripe/userforms vulnerable to remote code execution via userforms email subject
Details

Impact

The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.

Reported by

Jack Wallace from Bastion Security

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-27T16:53:17Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist / silverstripe/userforms

Package

Name
silverstripe/userforms
Purl
pkg:composer/silverstripe/userforms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.4.9

Affected versions

0.*
0.5.1
1.*
1.0.1
1.1.0-beta
2.*
2.0.1-rc1
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
3.*
3.0.0-beta1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.*
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.4.1
4.4.2
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.6.2
4.6.3
5.*
5.0.0-beta1
5.0.0-beta2
5.0.0
5.0.1
5.0.2
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0-rc1
5.6.0
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0-beta1
5.9.0-rc1
5.9.0
5.9.1
5.10.0-alpha1
5.10.0-beta1
5.10.0-rc1
5.10.0
5.11.0
5.11.1
5.12.0
5.12.1
5.12.2
5.13.0-beta1
5.13.0-rc1
5.13.0
5.13.1
5.13.2
5.13.3
5.13.4
5.14.0-beta1
5.14.0-rc1
5.14.0
5.14.1
5.14.2
5.14.3
5.15.0-beta1
5.15.0-rc1
5.15.0
5.15.1
5.15.2
5.15.3
5.15.4
5.15.5
5.15.6
5.15.7
5.15.8
5.15.9
5.15.10
5.15.11
v5.*
v5.9.2
6.*
6.0.0-beta1
6.0.0-rc1
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0-beta1
6.1.0-rc1
6.1.0
6.1.1
6.1.2
6.2.0-beta1
6.2.0-rc1
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.2.10
6.3.0-beta1
6.3.0-rc1
6.3.0
6.3.1
6.3.2
6.4.0-beta1
6.4.0-rc1
6.4.0
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.4.7
6.4.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-g8wr-r2v2-vqc6/GHSA-g8wr-r2v2-vqc6.json"

Packagist / silverstripe/userforms

Package

Name
silverstripe/userforms
Purl
pkg:composer/silverstripe/userforms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.7

Affected versions

7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-g8wr-r2v2-vqc6/GHSA-g8wr-r2v2-vqc6.json"

Packagist / silverstripe/userforms

Package

Name
silverstripe/userforms
Purl
pkg:composer/silverstripe/userforms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.1

Affected versions

7.*
7.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-g8wr-r2v2-vqc6/GHSA-g8wr-r2v2-vqc6.json"