CVE-2026-54717: Silverstripe Silverstripe-CMS

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.

Affected products

  • Silverstripe Silverstripe-CMS: before 6.2.1 (fixed in 6.2.1)

Published 2026-08-06. Last modified 2026-09-08.