GraphQL server for SilverStripe models and other data
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2023-44401 silverstripe/graphql is vulnerable to Incorrect Authorization in versions 4.0.0 - 4.3.7 and 5.0.0 - 5.1.3. | 4.0.0 - 4.3.75.0.0 - 5.1.3 | Medium |
CVE-2023-40180 silverstripe/graphql is vulnerable to Uncontrolled Resource Consumption in versions 3.0.0 - 3.8.2, 4.0.0 - 4.1.3, 4.2.0 - 4.2.5, 4.3.0 - 4.3.4 and 5.0.0 - 5.0.3. | 3.0.0 - 3.8.24.0.0 - 4.1.34.2.0 - 4.2.5 +2 more | High |
CVE-2023-28104 silverstripe/graphql is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.1.1 - 4.1.2 and 4.2.2 - 4.2.3. | 4.1.1 - 4.1.24.2.2 - 4.2.3 | High |
CVE-2019-12437 silverstripe/graphql is vulnerable to Cross-Site Request Forgery (CSRF) in versions 2.0.0 - 2.0.5 and 3.1.0 - 3.1.2. | 2.0.0 - 2.0.53.1.0 - 3.1.2 | High |
CVE-2021-28661 silverstripe/graphql is vulnerable to Incorrect Authorization in versions 3.0.0 - 3.5.2. | 3.0.0 - 3.5.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
m1/env Version ^2.2.0 | — | — |
guzzlehttp/psr7 Version ^2.7 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
webonyx/graphql-php Version ^15.19 | — | — |
silverstripe/framework Version ^6.1 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant