Known Vulnerabilities for Graphql by Silverstripe
Listed below are 3 of the newest known vulnerabilities associated with "Graphql" by "Silverstripe".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87719 json | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 befo... | Not Provided | 2026-09-12 | 2026-09-15 |
| CVE-2026-86176 json | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscr... | Not Provided | 2026-09-05 | 2026-09-05 |
| CVE-2026-86175 json | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticat... | Not Provided | 2026-09-05 | 2026-09-08 |
| CVE-2026-84799 json | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors,... | Not Provided | 2026-09-02 | 2026-09-04 |
| CVE-2026-84796 json | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to ... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82291 json | HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-ori... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-81643 json | Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscri... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-81636 json | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated clien... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-81633 json | Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id:... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-80223 json | Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive ... | Not Provided | 2026-08-30 | 2026-08-31 |