Skip to main content

Vendor/product archive

progress / sitefinity CVEs

Beta · best-effort

24 CVEs tagged to progress / sitefinity6 Critical, 9 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-7313

Published Jun 2, 2026

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7312

Published Jun 2, 2026

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 1…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7201

Published Jun 2, 2026

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7198

Published Jun 2, 2026

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restri…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7195

Published Jun 2, 2026

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x b…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11627

Published Jan 7, 2025

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11626

Published Jan 7, 2025

Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue aff…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11625

Published Jan 7, 2025

Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 t…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27636

Published Jun 16, 2024

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1632

Published Feb 28, 2024

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6784

Published Dec 20, 2023

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29376

Published Apr 10, 2023

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is pote…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29375

Published Apr 10, 2023

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is pote…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17392

Published Nov 26, 2019

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7215

Published Jun 6, 2019

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. T…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17055

Published Sep 28, 2018

An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18179

Published Feb 12, 2018

Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18178

Published Feb 12, 2018

Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18177

Published Feb 12, 2018

Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18176

Published Feb 12, 2018

Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18175

Published Feb 12, 2018

Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixe…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15883

Published Jan 8, 2018

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or ga…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9248

Published Jul 3, 2017

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryption…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
50.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1