HIGH 8.8
GHSA-g8wr-r2v2-vqc6
silverstripe/userforms vulnerable to remote code execution via userforms email subject
Quick fix
GHSA-g8wr-r2v2-vqc6 — silverstripe/userforms: upgrade to the fixed version with the command below.
composer require silverstripe/userforms:^6.4.9 Details
### Impact The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.
### Reported by Jack Wallace from Bastion Security
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / silverstripe/userforms
Introduced in:
0 Fixed in: 6.4.9 Fix
composer require silverstripe/userforms:^6.4.9 Packagist / silverstripe/userforms
Introduced in:
7.0.0 Fixed in: 7.0.7 Fix
composer require silverstripe/userforms:^7.0.7 Packagist / silverstripe/userforms
Introduced in:
7.1.0 Fixed in: 7.1.1 Fix
composer require silverstripe/userforms:^7.1.1 References
- https://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6 [WEB]
- https://github.com/silverstripe/silverstripe-userforms/pull/1441 [WEB]
- https://github.com/silverstripe/silverstripe-userforms/pull/1442 [WEB]
- https://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702 [WEB]
- https://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c [WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yaml [WEB]
- https://github.com/silverstripe/silverstripe-userforms [PACKAGE]
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9 [WEB]
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/7.0.7 [WEB]
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/7.1.1 [WEB]
- https://www.silverstripe.org/download/security-releases/cve-2026-54721 [WEB]