CVE-2020-9280
CVE-2020-9280 is a high-severity vulnerability in Silverstripe with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-434.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 2% (75th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-434
- Affected product: Silverstripe
- Published:
- Last modified:
Description
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x.
Frequently asked questions
- What is CVE-2020-9280?
- In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x.
- How severe is CVE-2020-9280?
- CVE-2020-9280 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2020-9280 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (75th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-9280?
- CVE-2020-9280 affects Silverstripe. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-9280?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2020-9280 published?
- CVE-2020-9280 was published on 2020-04-15 and last updated on 2026-06-17.
References
- https://forum.silverstripe.org/c/releases
- https://www.silverstripe.org/download/security-releases/
- https://www.silverstripe.org/download/security-releases/cve-2020-9280
Affected products (1)
- cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*
More vulnerabilities in Silverstripe
- CVE-2007-2321 — Critical (CVSS 10.0): Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.
- CVE-2019-12204 — Critical (CVSS 9.8): In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to…
- CVE-2019-5715 — Critical (CVSS 9.8): All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5,…
- CVE-2019-12437 — High (CVSS 8.8): In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in…
- CVE-2020-6164 — High (CVSS 7.5): In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can…
- CVE-2011-4960 — High (CVSS 7.5): SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6…
All CVEs affecting Silverstripe →
Other CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities
- CVE-2026-75949 — Critical (CVSS 10.0): Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 -…
- CVE-2026-74803 — Critical (CVSS 10.0): Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts…
- CVE-2026-66665 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-61900 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla…
- CVE-2026-61424 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla…
- CVE-2026-57719 — Critical (CVSS 10.0): Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using…
Browse all CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities →