Squidex.io / Squidex
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-24736 | Squidex has Server-Side Request Forgery (SSRF) Issue in Webhook Configuration | CRITICAL | 9.1 | Jan 27, 2026 |
| CVE-2023-46857 | Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, a… | MEDIUM | 5.4 | Dec 7, 2023 |
| CVE-2023-46252 | Cross-Site Scripting (XSS) via postMessage Handler in Squidex | MEDIUM | 6.8 | Nov 7, 2023 |
| CVE-2023-46253 | Remote code execution in Squidex | CRITICAL | 9.1 | Nov 7, 2023 |
| CVE-2023-46744 | Stored Cross-site Scripting in Squidex | MEDIUM | 5.4 | Nov 7, 2023 |
| CVE-2023-3580 | Improper Handling of Additional Special Element in squidex/squidex | MEDIUM | 4.3 | Jul 10, 2023 |
| CVE-2023-24278 | Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability. | MEDIUM | 6.1 | Mar 18, 2023 |
| CVE-2023-0643 | Improper Handling of Additional Special Element in squidex/squidex | MEDIUM | 6.1 | Feb 2, 2023 |
| CVE-2023-0642 | Cross-Site Request Forgery (CSRF) in squidex/squidex | MEDIUM | 6.5 | Feb 2, 2023 |
Showing 1 to 9 of 9 CVEs