CVE-2026-24736
- EPSS 0.08%
- Veröffentlicht 27.01.2026 20:54:51
- Zuletzt bearbeitet 12.02.2026 21:30:02
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook conf...
CVE-2023-46857
- EPSS 0.73%
- Veröffentlicht 07.12.2023 06:15:54
- Zuletzt bearbeitet 21.11.2024 08:29:26
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with ...
CVE-2023-46253
- EPSS 4.45%
- Veröffentlicht 07.11.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:28:10
Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squide...
CVE-2023-46252
- EPSS 0.27%
- Veröffentlicht 07.11.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:28:10
Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different ...
CVE-2023-46744
- EPSS 0.2%
- Veröffentlicht 07.11.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:29:12
Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS at...
CVE-2023-3580
- EPSS 0.09%
- Veröffentlicht 10.07.2023 16:15:56
- Zuletzt bearbeitet 21.11.2024 08:17:35
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
CVE-2023-24278
- EPSS 60.73%
- Veröffentlicht 18.03.2023 04:16:02
- Zuletzt bearbeitet 26.02.2025 19:15:16
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
CVE-2023-0642
- EPSS 0.13%
- Veröffentlicht 02.02.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:32
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
CVE-2023-0643
- EPSS 0.43%
- Veröffentlicht 02.02.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:32
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.