Squidex.io
Squidex.io Squidex: vulnerabilidades y CVE
Squidex.io Squidex tiene 13 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41177 | Media (5.5) | 0.43% | — | 22 abr 2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails… |
| CVE-2026-41172 | Alta (7.3) | 0.36% | — | 22 abr 2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary… |
| CVE-2026-41171 | Alta (7.3) | 0.36% | — | 22 abr 2026 | Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP… |
| CVE-2026-41170 | Alta (7.2) | 0.40% | — | 22 abr 2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for… |
| CVE-2026-24736 | Alta (8.8) | 0.48% | — | 27 ene 2026 | Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The… |
| CVE-2023-46857 | Media (5.4) | 0.57% | — | 7 dic 2023 | Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME… |
| CVE-2023-46253 | Alta (7.2) | 1.5% | — | 7 nov 2023 | Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain… |
| CVE-2023-46252 | Media (6.1) | 0.47% | — | 7 nov 2023 | Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The… |
| CVE-2023-46744 | Media (5.4) | 0.50% | — | 7 nov 2023 | Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering… |
| CVE-2023-3580 | Media (4.3) | 0.64% | — | 10 jul 2023 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. |
| CVE-2023-24278 | Media (6.1) | 2.9% | — | 18 mar 2023 | Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability. |
| CVE-2023-0643 | Media (6.1) | 0.58% | — | 2 feb 2023 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. |
| CVE-2023-0642 | Media (6.5) | 0.41% | — | 2 feb 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.