CVE-2026-55779: silverstripe/versioned has XSS in archive admin restore
It’s possible to use the page title as an XSS vector when restoring a page in ArchiveAdmin
References
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/versioned/CVE-2026-55779.yaml
- github.com/advisories/GHSA-m4g4-86qc-v8w7
- github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952
- github.com/silverstripe/silverstripe-versioned/pull/541
- github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1
- github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7
- nvd.nist.gov/vuln/detail/CVE-2026-55779
- www.silverstripe.org/download/security-releases/cve-2026-55779
Code Behaviors & Features
Detect and mitigate CVE-2026-55779 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →