Known Vulnerabilities for Assets by Silverstripe
Listed below are 2 of the newest known vulnerabilities associated with "Assets" by "Silverstripe".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62415 json | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-60755 json | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions t... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60749 json | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions t... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60024 json | The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-56812 json | Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) a... | Not Provided | 2026-07-07 | 2026-07-07 |
| CVE-2026-56394 json | Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extensi... | Not Provided | 2026-06-21 | 2026-06-23 |
| CVE-2026-56385 json | Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56384 json | Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without p... | Not Provided | 2026-06-21 | 2026-06-24 |
| CVE-2026-55605 json | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted H... | Not Provided | 2026-07-09 | 2026-07-10 |
| CVE-2026-55515 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes on... | Not Provided | 2026-07-10 | 2026-07-13 |