MEDIUM 5.4
GHSA-w3cp-g2pf-65wh
Silverstripe: XSS in breadcrumbs in page list view
Quick fix
GHSA-w3cp-g2pf-65wh — silverstripe/cms: upgrade to the fixed version with the command below.
composer require silverstripe/cms:^6.2.1 Details
### Impact Page breadcrumbs in the CMS are vulnerable to XSS when viewed using the page list view
### Reporter Fase Rais Baradika
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / silverstripe/cms
Introduced in:
0 Fixed in: 6.2.1 Fix
composer require silverstripe/cms:^6.2.1 References
- https://github.com/silverstripe/silverstripe-cms/security/advisories/GHSA-w3cp-g2pf-65wh [WEB]
- https://github.com/silverstripe/silverstripe-cms/pull/3175 [WEB]
- https://github.com/silverstripe/silverstripe-cms/commit/62f9912baa18c80304f3fa8b6eca71bb5dc2d21e [WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/cms/CVE-2026-54717.yaml [WEB]
- https://github.com/silverstripe/silverstripe-cms [PACKAGE]
- https://github.com/silverstripe/silverstripe-cms/releases/tag/6.2.1 [WEB]
- https://www.silverstripe.org/download/security-releases/cve-2026-54717 [WEB]