
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55779 is a stored Cross-Site Scripting (XSS) vulnerability in the silverstripe/versioned Composer package (Silverstripe Versioned) affecting all versions prior to 3.2.1. The flaw exists in RestoreAction::getRestoreMessage() within src/RestoreAction.php, where user-controlled fields (Title, URLSegment, CMSEditLink(), and changedProperty['value']) are inserted into an HTML-rendered restoration notification without applying Convert::raw2xml() encoding. It was discovered and disclosed on June 24, 2026, with the fix released the same day. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Feedly).
The root cause is improper output encoding (CWE-79) in the getRestoreMessage() method of RestoreAction.php. The method builds an ArchiveAdmin restore notification rendered as CAST_HTML but interpolates $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and $changedProperty['value'] directly into the HTML string without escaping. An attacker who can create or modify a page with a crafted title or URL segment (e.g., <iframe src=javascript:alert(1)> or <button formaction="javascript:alert(1)">) can store a malicious payload that executes when an administrator restores the archived page in the CMS. The fix applies Convert::raw2xml() to all user-supplied values before interpolation (GitHub Commit, GitHub Advisory).
Successful exploitation allows stored JavaScript to execute in the browser of a CMS administrator who restores an archived page, compromising the confidentiality and integrity of the administrator's CMS session. An attacker could steal session cookies, perform unauthorized CMS actions (such as modifying content or creating admin accounts), or conduct further attacks against the CMS backend. Availability is not directly impacted, and the scope is limited to the CMS session of the triggering administrator (GitHub Advisory, Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that an attacker be able to create or manipulate a page with a crafted title or URL segment prior to archival, and that a CMS administrator subsequently restores that page — making it a stored XSS with a required user interaction step (Feedly).
Title or URLSegment field to a JavaScript payload, e.g., <iframe src=javascript:alert(document.cookie)> or <button formaction="javascript:alert(1)">Click</button>.RestoreAction::getRestoreMessage() builds the notification message using the unescaped Title or URLSegment, and the message is rendered as HTML (CAST_HTML) in the administrator's browser, executing the injected JavaScript.Title or URLSegment fields containing HTML tags such as <script>, <iframe>, <button formaction=...>, or JavaScript URI schemes (javascript:).Upgrade silverstripe/versioned to version 3.2.1 or later, which applies Convert::raw2xml() to all user-supplied fields (Title, URLSegment, CMSEditLink(), and changedProperty['value']) before rendering the restore notification message (GitHub Release, GitHub Advisory). As interim mitigations, enforce a Content Security Policy (CSP) that disallows inline script execution in the CMS, and restrict page creation/editing privileges to trusted users only. Note that the fix has not been backported to the Silverstripe 5 (silverstripe-versioned v2) branch as of the disclosure date; Silverstripe 5 users should consult the official security release blog for guidance (Silverstripe Blog).
The vulnerability was reported by Steve Boyd of Silverstripe Ltd. and fixed by developer emteknetnz (GitHub Advisory). Community discussion on the fix pull request raised concerns that the patch was not backported to Silverstripe 5 (silverstripe-versioned v2), leaving non-EOL Silverstripe 5.4 installations without a direct fix. A community member (xini) criticized the project's security backport policy, arguing it leaves supported versions knowingly vulnerable and that the contribution process needs to be more open to address such issues promptly (GitHub PR #541). Silverstripe acknowledged the concern and published a security release blog post addressing the situation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."