VYPR

Squidex

by Squidex.io

CVEs (7)

  • CVE-2026-24736CriJan 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to…

  • CVE-2023-46253CriNov 7, 2023
    risk 0.59cvss 9.1epss 0.02

    Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squidex allows users with the…

  • CVE-2023-46252MedNov 7, 2023
    risk 0.44cvss 6.8epss 0.00

    Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different class-like functions, which…

  • CVE-2023-46857MedDec 7, 2023
    risk 0.35cvss 5.4epss 0.01

    Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is…

  • CVE-2023-46744MedNov 7, 2023
    risk 0.35cvss 5.4epss 0.01

    Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS attacks through uploaded SVG…

  • CVE-2026-31016Jun 29, 2026
    risk 0.00cvss epss 0.00

    Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint

  • CVE-2023-3580MedJul 10, 2023
    risk 0.00cvss 4.3epss 0.01

    Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.