SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-54721

HIGH · CVSS 8.8 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Silverstripe UserForms versions 6.0.0 to 6.4.9, 7.0.7, and 7.1.1 are vulnerable due to a flaw in the email recipient subject field, which allows authenticated users to inject and execute arbitrary server-side code. This vulnerability poses a significant risk to the confidentiality, integrity, and availability of the system. Organizations using affected versions should prioritize updating to the patched releases to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54721
Severity
HIGH
CVSS
8.8
EPSS
0.41%

Original NVD Description

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code on the server, compromising confidentiality, integrity, and availability. This issue is fixed in versions 6.4.9, 7.0.7, and 7.1.1.