VendorsSquidex.iosquidexany version
Vulnerabilities

Squidex.io Squidex any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-24736
Squidex has Server-Side Request Forgery (SSRF) Issue in Webhook Configuration
Published 2026-01-27 · Analyzed
9.1EPSS 0.005
CVE-2023-0642
Cross-Site Request Forgery (CSRF) in squidex/squidex
Published 2023-02-02 · Modified
6.8EPSS 0.004
CVE-2023-24278
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
Published 2023-03-18 · Modified
6.1EPSS 0.029
CVE-2023-0643
Improper Handling of Additional Special Element in squidex/squidex
Published 2023-02-02 · Modified
6.1EPSS 0.006
CVE-2023-3580
Improper Handling of Additional Special Element in squidex/squidex
Published 2023-07-10 · Modified
5.4EPSS 0.006
CVE-2023-46857
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.
Published 2023-12-07 · Modified
5.4EPSS 0.006
CVE-2023-46744
Stored Cross-site Scripting in Squidex
Published 2023-11-07 · Modified
5.4EPSS 0.005