Progress
Progress Sitefinity: vulnerabilidades y CVE
Progress Sitefinity tiene 26 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses5
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-9248 | Crítica (9.8) | 75% | ⚠ Explotación activa | 3 jul 2017 | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-7313 | Media (4.9) | 0.51% | — | 2 jun 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity… |
| CVE-2026-7312 | Alta (7.5) | 0.55% | — | 2 jun 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to… |
| CVE-2026-7201 | Alta (8.8) | 0.55% | — | 2 jun 2026 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to… |
| CVE-2026-7198 | Crítica (9.8) | 0.65% | — | 2 jun 2026 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of… |
| CVE-2026-7195 | Alta (8.1) | 0.62% | — | 2 jun 2026 | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before… |
| CVE-2025-1968 | Alta (7.7) | 0.32% | — | 9 abr 2025 | Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity:… |
| CVE-2024-11627 | Alta (8.1) | 0.33% | — | 7 ene 2025 | : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through… |
| CVE-2024-11626 | Media (4.8) | 0.36% | — | 7 ene 2025 | Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through… |
| CVE-2024-11625 | Media (5.3) | 0.30% | — | 7 ene 2025 | Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through… |
| CVE-2024-4882 | Media (5.3) | 0.38% | — | 8 jul 2024 | The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions. |
| CVE-2023-27636 | Media (5.4) | 1.3% | — | 16 jun 2024 | Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. |
| CVE-2024-1636 | Media (5.4) | 0.40% | — | 28 feb 2024 | Potential Cross-Site Scripting (XSS) in the page editing area. |
| CVE-2024-1632 | Media (6.5) | 0.50% | — | 28 feb 2024 | Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area. |
| CVE-2023-6784 | Media (4.3) | 0.38% | — | 20 dic 2023 | A malicious user could potentially use the Sitefinity system for the distribution of phishing emails. |
| CVE-2023-29376 | Media (5.4) | 0.41% | — | 10 abr 2023 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in… |
| CVE-2023-29375 | Crítica (9.8) | 0.82% | — | 10 abr 2023 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through… |
| CVE-2019-17392 | Crítica (9.8) | 1.1% | — | 26 nov 2019 | Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled. |
| CVE-2019-7215 | Media (6.5) | 1.0% | — | 6 jun 2019 | Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to… |
| CVE-2018-17055 | Alta (7.5) | 0.97% | — | 28 sept 2018 | An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. |
| CVE-2017-18179 | Alta (8.8) | 2.8% | — | 12 feb 2018 | Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in… |
| CVE-2017-18178 | Media (6.1) | 2.3% | — | 12 feb 2018 | Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1. |
| CVE-2017-18177 | Media (5.4) | 0.70% | — | 12 feb 2018 | Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1. |
| CVE-2017-18176 | Media (5.4) | 0.70% | — | 12 feb 2018 | Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1. |
| CVE-2017-18175 | Media (5.4) | 0.70% | — | 12 feb 2018 | Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1. |
| CVE-2017-15883 | Crítica (9.8) | 1.9% | — | 8 ene 2018 | Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to… |
| CVE-2017-9248 | Crítica (9.8) | 75% | ⚠ Explotación activa | 3 jul 2017 | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.