GHSA-m4g4-86qc-v8w7: XSS
Published Aug 28, 2026
·Updated
Impact It's possible to use the page title as an XSS vector when restoring a page in ArchiveAdmin
Reporter Steve Boyd Silverstripe Ltd.
Affected Software
1 affected componentFixes available
composer/silverstripe/versioned<3.2.1
3.2.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/silverstripe/versionedto a version that resolves this vulnerability.Fixed in 3.2.1
Event History
Aug 28, 2026
Advisory Published
via GitHub·10:19 PM
Data Sourced
via GitHub·10:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What action triggers the vulnerable code path?
The issue occurs when a page is restored in ArchiveAdmin. The page title can be used as the XSS payload during that restoration process.
2
Does exploitation require attacker authentication or special privileges?
The supplied CVSS vector indicates no privileges are required by the attacker. However, the vector also indicates user interaction is required.
3
What is the expected impact of a successful exploit?
The issue is rated medium severity with low confidentiality and integrity impact. No availability impact is indicated.