Progress / Sitefinity
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-7313 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity | HIGH | 8.7 | Jun 2, 2026 |
| CVE-2026-7312 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity | CRITICAL | 10.0 | Jun 2, 2026 |
| CVE-2026-7201 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity | HIGH | 8.8 | Jun 2, 2026 |
| CVE-2026-7198 | CWE-284: Improper Access Control in web services in Progress Sitefinity | CRITICAL | 9.8 | Jun 2, 2026 |
| CVE-2026-7195 | CWE-20: Improper Input Validation in web services in Progress Sitefinity | HIGH | 8.8 | Jun 2, 2026 |
| CVE-2025-1968 | Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session… | HIGH | 7.7 | Apr 9, 2025 |
| CVE-2024-11627 | : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, fro… | HIGH | 8.1 | Jan 7, 2025 |
| CVE-2024-11626 | Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitef… | HIGH | 8.4 | Jan 7, 2025 |
| CVE-2024-11625 | Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.81… | HIGH | 7.7 | Jan 7, 2025 |
| CVE-2024-4882 | URL Redirection to Arbitrary Site Exists in Sitefinity | MEDIUM | 5.3 | Jul 8, 2024 |
| CVE-2023-27636 | Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. | MEDIUM | 6.5 | Jun 16, 2024 |
| CVE-2024-1636 | Potential Cross-Site Scripting (XSS) in the page editing area | HIGH | 8.0 | Feb 28, 2024 |
| CVE-2024-1632 | Incorrect access control in the Sitefinity backend | HIGH | 8.8 | Feb 28, 2024 |
| CVE-2023-6784 | Potential Use of the Sitefinity System for Distribution of Phishing Emails | MEDIUM | 4.7 | Dec 20, 2023 |
| CVE-2023-29376 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3… | MEDIUM | 5.4 | Apr 10, 2023 |
| CVE-2023-29375 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3… | CRITICAL | 9.8 | Apr 10, 2023 |
| CVE-2019-17392 | Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled. | CRITICAL | 9.8 | Nov 26, 2019 |
| CVE-2019-7215 | Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid o… | MEDIUM | 6.5 | Jun 6, 2019 |
| CVE-2018-17055 | An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. | HIGH | 7.5 | Sep 28, 2018 |
| CVE-2017-18179 | Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also… | HIGH | 8.8 | Feb 12, 2018 |
| CVE-2017-18178 | Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is spe… | MEDIUM | 6.1 | Feb 12, 2018 |
| CVE-2017-18177 | Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1. | MEDIUM | 5.4 | Feb 12, 2018 |
| CVE-2017-18176 | Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10… | MEDIUM | 5.4 | Feb 12, 2018 |
| CVE-2017-18175 | Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG e… | MEDIUM | 5.4 | Feb 12, 2018 |
| CVE-2017-15883 | Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load… | CRITICAL | 9.8 | Jan 8, 2018 |
Showing 1 to 24 of 24 CVEs