THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g8wr-r2v2-vqc6 (high) — silverstripe/userforms vulnerable to remote code execution via userforms email subject

[GHSA] GHSA-g8wr-r2v2-vqc6 (high) — silverstripe/userforms vulnerable to remote code execution via userforms email subject

medgithub_advisoriesPublished 2026-08-27

GHSA-g8wr-r2v2-vqc6 Severity: high CVE: CVE-2026-54721

silverstripe/userforms vulnerable to remote code execution via userforms email subject

### Impact The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.

### Reported by Jack Wallace from Bastion Security

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g8wr-r2v2-vqc6