Sitefinity
CVEs (31)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17053 | Med | 0.40 | 6.1 | 0.01 | Oct 3, 2018 | Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054. | ||
| CVE-2018-17056 | Med | 0.40 | 6.1 | 0.01 | Sep 28, 2018 | Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2017-18178 | Med | 0.40 | 6.1 | 0.02 | Feb 12, 2018 | Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1. | ||
| CVE-2017-9140 | Med | 0.40 | 6.1 | 0.10 | May 22, 2017 | Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to… | ||
| CVE-2023-27636 | Med | 0.38 | 5.4 | 0.01 | Jun 16, 2024 | Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. | ||
| CVE-2023-29376 | Med | 0.35 | 5.4 | 0.00 | Apr 10, 2023 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries. | ||
| CVE-2017-18177 | Med | 0.35 | 5.4 | 0.01 | Feb 12, 2018 | Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1. | ||
| CVE-2017-18176 | Med | 0.35 | 5.4 | 0.01 | Feb 12, 2018 | Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1. | ||
| CVE-2017-18175 | Med | 0.35 | 5.4 | 0.01 | Feb 12, 2018 | Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1. | ||
| CVE-2024-4882 | Med | 0.34 | — | 0.00 | Jul 8, 2024 | The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions. | ||
| CVE-2023-6784 | Med | 0.31 | 4.7 | 0.00 | Dec 20, 2023 | A malicious user could potentially use the Sitefinity system for the distribution of phishing emails. |
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.02
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
- risk 0.40cvss 6.1epss 0.10
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to…
- risk 0.38cvss 5.4epss 0.01
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
- risk 0.35cvss 5.4epss 0.01
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
- risk 0.35cvss 5.4epss 0.01
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
- risk 0.35cvss 5.4epss 0.01
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
- risk 0.34cvss —epss 0.00
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
- risk 0.31cvss 4.7epss 0.00
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
Page 2 of 2