CVE-2019-12149: Silverstripe Registry

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.

Affected products

  • Silverstripe Registry: from 2.1.0, before 2.1.1 (fixed in 2.1.1); from 2.2.0, before 2.2.1 (fixed in 2.2.1)
  • Silverstripe Restfulserver: from 1.0.1, before 1.0.9 (fixed in 1.0.9); from 2.0.0, before 2.0.4 (fixed in 2.0.4)

Published 2019-06-11. Last modified 2026-06-17.