AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-16409

MEDIUM · CVSS 5.3 EPSS 1.20% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-09-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-16409
Severity
MEDIUM
CVSS
5.3
EPSS
1.20%

Original NVD Description

In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users who upgrade from SilverStripe 3.x to 4.x and had Versioned Files installed have no further need for this module, because the 4.x release has built-in versioning. However, nothing in the upgrade process automates the destruction of these insecure artefacts, nor alerts the user to the criticality of destruction.)