CVE-2020-26138: Silverstripe

Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.

In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.

Affected products

  • Silverstripe Silverstripe: before 4.6.0 (fixed in 4.6.0); version 4.6.0 only

Published 2021-06-08. Last modified 2026-06-17.