« Volver al listado

Progress

Progress Sitefinity: vulnerabilidades y CVE

Progress Sitefinity tiene 26 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE26
Últimos 12 meses5
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2017-9248Crítica (9.8)75%⚠ Explotación activa3 jul 2017
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-7313Media (4.9)0.51%—2 jun 2026
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity…
CVE-2026-7312Alta (7.5)0.55%—2 jun 2026
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to…
CVE-2026-7201Alta (8.8)0.55%—2 jun 2026
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to…
CVE-2026-7198Crítica (9.8)0.65%—2 jun 2026
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of…
CVE-2026-7195Alta (8.1)0.62%—2 jun 2026
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before…
CVE-2025-1968Alta (7.7)0.32%—9 abr 2025
Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity:…
CVE-2024-11627Alta (8.1)0.33%—7 ene 2025
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through…
CVE-2024-11626Media (4.8)0.36%—7 ene 2025
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through…
CVE-2024-11625Media (5.3)0.30%—7 ene 2025
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through…
CVE-2024-4882Media (5.3)0.38%—8 jul 2024
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
CVE-2023-27636Media (5.4)1.3%—16 jun 2024
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
CVE-2024-1636Media (5.4)0.40%—28 feb 2024
Potential Cross-Site Scripting (XSS) in the page editing area.
CVE-2024-1632Media (6.5)0.50%—28 feb 2024
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
CVE-2023-6784Media (4.3)0.38%—20 dic 2023
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
CVE-2023-29376Media (5.4)0.41%—10 abr 2023
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in…
CVE-2023-29375Crítica (9.8)0.82%—10 abr 2023
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through…
CVE-2019-17392Crítica (9.8)1.1%—26 nov 2019
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
CVE-2019-7215Media (6.5)1.0%—6 jun 2019
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to…
CVE-2018-17055Alta (7.5)0.97%—28 sept 2018
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
CVE-2017-18179Alta (8.8)2.8%—12 feb 2018
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in…
CVE-2017-18178Media (6.1)2.3%—12 feb 2018
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
CVE-2017-18177Media (5.4)0.70%—12 feb 2018
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
CVE-2017-18176Media (5.4)0.70%—12 feb 2018
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
CVE-2017-18175Media (5.4)0.70%—12 feb 2018
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
CVE-2017-15883Crítica (9.8)1.9%—8 ene 2018
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to…
CVE-2017-9248Crítica (9.8)75%⚠ Explotación activa3 jul 2017
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1203 Exploitation for Client Execution2
  3. T1078 Valid Accounts1
  4. T1078.001 Default Accounts1
  5. T1078.002 Domain Accounts1
  6. T1098.002 Additional Email Delegate Permissions1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Progress