VYPR

Sitefinity

by Progress (organisation)

CVEs (31)

  • CVE-2018-17053MedOct 3, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054.

  • CVE-2018-17056MedSep 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2017-18178MedFeb 12, 2018
    risk 0.40cvss 6.1epss 0.02

    Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.

  • CVE-2017-9140MedMay 22, 2017
    risk 0.40cvss 6.1epss 0.10

    Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to…

  • CVE-2023-27636MedJun 16, 2024
    risk 0.38cvss 5.4epss 0.01

    Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

  • CVE-2023-29376MedApr 10, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.

  • CVE-2017-18177MedFeb 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.

  • CVE-2017-18176MedFeb 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.

  • CVE-2017-18175MedFeb 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.

  • CVE-2024-4882MedJul 8, 2024
    risk 0.34cvss epss 0.00

    The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.

  • CVE-2023-6784MedDec 20, 2023
    risk 0.31cvss 4.7epss 0.00

    A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

Page 2 of 2