Vulnerabilities > Progress > Sitefinity > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-16 | CVE-2023-27636 | Cross-site Scripting vulnerability in Progress Sitefinity Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. | 5.4 |
2024-02-28 | CVE-2024-1632 | Unspecified vulnerability in Progress Sitefinity Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area. | 6.5 |
2024-02-28 | CVE-2024-1636 | Cross-site Scripting vulnerability in Progress Sitefinity Potential Cross-Site Scripting (XSS) in the page editing area. | 5.4 |
2023-12-20 | CVE-2023-6784 | Unspecified vulnerability in Progress Sitefinity A malicious user could potentially use the Sitefinity system for the distribution of phishing emails. | 4.3 |
2023-04-10 | CVE-2023-29376 | Cross-site Scripting vulnerability in Progress Sitefinity An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. | 5.4 |
2019-06-06 | CVE-2019-7215 | Insufficient Session Expiration vulnerability in Progress Sitefinity Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. | 6.5 |
2018-02-12 | CVE-2017-18178 | Open Redirect vulnerability in Progress Sitefinity 9.1 Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. | 6.1 |
2018-02-12 | CVE-2017-18177 | Cross-site Scripting vulnerability in Progress Sitefinity 9.1 Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. | 5.4 |
2018-02-12 | CVE-2017-18176 | Cross-site Scripting vulnerability in Progress Sitefinity 9.1 Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. | 5.4 |
2018-02-12 | CVE-2017-18175 | Cross-site Scripting vulnerability in Progress Sitefinity 9.1 Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. | 5.4 |