VendorsProgresssitefinityall versions
Vulnerabilities

Progress Sitefinity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2026-7312
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
10.0EPSS 0.004
CVE-2017-9248
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
Published 2017-07-03 · Analyzed
9.8KEV1 PoCEPSS 0.751
CVE-2017-15883
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
Published 2018-01-08 · Modified
9.8EPSS 0.019
CVE-2019-17392
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Published 2019-11-26 · Modified
9.8EPSS 0.011
CVE-2023-29375
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.
Published 2023-04-10 · Modified
9.8EPSS 0.008
CVE-2026-7198
CWE-284: Improper Access Control in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
9.8EPSS 0.004
CVE-2017-18179
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.
Published 2018-02-12 · Modified
8.8EPSS 0.028
CVE-2024-1632
Incorrect access control in the Sitefinity backend
Published 2024-02-28 · Analyzed
8.8EPSS 0.005
CVE-2026-7195
CWE-20: Improper Input Validation in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
8.8EPSS 0.005
CVE-2026-7201
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
8.8EPSS 0.003
CVE-2026-7313
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
8.7EPSS 0.003
CVE-2024-11626
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Published 2025-01-07 · Analyzed
8.4EPSS 0.004
CVE-2024-11627
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Published 2025-01-07 · Analyzed
8.1EPSS 0.003
CVE-2024-1636
Potential Cross-Site Scripting (XSS) in the page editing area
Published 2024-02-28 · Analyzed
8.0EPSS 0.004
CVE-2024-11625
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Published 2025-01-07 · Analyzed
7.7EPSS 0.003
CVE-2018-17055
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
Published 2018-09-28 · Modified
7.5EPSS 0.010
CVE-2023-27636
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
Published 2024-06-16 · Modified
6.51 PoCEPSS 0.013
CVE-2019-7215
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
Published 2019-06-06 · Modified
6.5EPSS 0.010
CVE-2017-18178
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
Published 2018-02-12 · Modified
6.1EPSS 0.023
CVE-2017-18175
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
Published 2018-02-12 · Modified
5.4EPSS 0.007
CVE-2017-18176
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
Published 2018-02-12 · Modified
5.4EPSS 0.007
CVE-2017-18177
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
Published 2018-02-12 · Modified
5.4EPSS 0.007
CVE-2023-29376
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
Published 2023-04-10 · Modified
5.4EPSS 0.004
CVE-2023-6784
Potential Use of the Sitefinity System for Distribution of Phishing Emails
Published 2023-12-20 · Modified
4.7EPSS 0.004