{"id":"CVE-2026-54721","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54721","summary":"silverstripe/userforms vulnerable to remote code execution via userforms email subject","details":"### Impact\nThe userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.\n\n### Reported by\nJack Wallace from Bastion Security","published":"2026-08-27T16:53:17Z","modified":"2026-08-27T17:00:40.963152789Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/userforms","fixedVersion":"6.4.9"},{"ecosystem":"Packagist","name":"silverstripe/userforms","fixedVersion":"7.0.7"},{"ecosystem":"Packagist","name":"silverstripe/userforms","fixedVersion":"7.1.1"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-userforms/pull/1441","label":"silverstripe/silverstripe-userforms#1441"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/pull/1441"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/pull/1442"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-userforms"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/releases/tag/7.0.7"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/releases/tag/7.1.1"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/cve-2026-54721"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T17:00:40.963152789Z"}}