Skip to main content

Vendor/product archive

squidex.io / squidex CVEs

Beta · best-effort

9 CVEs tagged to squidex.io / squidex2 Critical, 0 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-24736

Published Jan 27, 2026

Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46857

Published Dec 7, 2023

Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46253

Published Nov 7, 2023

Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allow…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46252

Published Nov 7, 2023

Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46744

Published Nov 7, 2023

Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authentic…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3580

Published Jul 10, 2023

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24278

Published Mar 18, 2023

Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0643

Published Feb 2, 2023

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0642

Published Feb 2, 2023

Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1