CVE-2024-11627
- EPSS 0.07%
- Veröffentlicht 07.01.2025 08:15:24
- Zuletzt bearbeitet 29.07.2025 19:33:08
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15....
CVE-2024-11626
- EPSS 0.07%
- Veröffentlicht 07.01.2025 08:15:24
- Zuletzt bearbeitet 29.07.2025 19:34:11
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15....
CVE-2024-11625
- EPSS 0.05%
- Veröffentlicht 07.01.2025 08:15:24
- Zuletzt bearbeitet 29.07.2025 19:35:07
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 thro...
CVE-2023-27636
- EPSS 0.25%
- Veröffentlicht 16.06.2024 21:15:50
- Zuletzt bearbeitet 21.11.2024 07:53:18
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
CVE-2024-1636
- EPSS 0.07%
- Veröffentlicht 28.02.2024 12:15:47
- Zuletzt bearbeitet 16.12.2024 21:05:49
Potential Cross-Site Scripting (XSS) in the page editing area.
CVE-2024-1632
- EPSS 2.18%
- Veröffentlicht 28.02.2024 12:15:46
- Zuletzt bearbeitet 16.12.2024 21:04:13
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
CVE-2023-6784
- EPSS 0.02%
- Veröffentlicht 20.12.2023 14:15:22
- Zuletzt bearbeitet 21.11.2024 08:44:33
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
CVE-2023-29376
- EPSS 0.05%
- Veröffentlicht 10.04.2023 15:15:07
- Zuletzt bearbeitet 11.02.2025 16:15:38
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
CVE-2023-29375
- EPSS 1.54%
- Veröffentlicht 10.04.2023 15:15:07
- Zuletzt bearbeitet 12.02.2025 15:15:11
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.
CVE-2019-17392
- EPSS 0.49%
- Veröffentlicht 26.11.2019 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:32:14
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.