« Back to list

Squidex.io

Squidex.io Squidex: vulnerabilities and CVEs

Squidex.io Squidex has 13 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs13
Last 12 months5
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-41177Medium (5.5)0.43%—Apr 22, 2026
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails…
CVE-2026-41172High (7.3)0.36%—Apr 22, 2026
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary…
CVE-2026-41171High (7.3)0.36%—Apr 22, 2026
Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP…
CVE-2026-41170High (7.2)0.40%—Apr 22, 2026
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for…
CVE-2026-24736High (8.8)0.48%—Jan 27, 2026
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The…
CVE-2023-46857Medium (5.4)0.57%—Dec 7, 2023
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME…
CVE-2023-46253High (7.2)1.5%—Nov 7, 2023
Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain…
CVE-2023-46252Medium (6.1)0.47%—Nov 7, 2023
Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The…
CVE-2023-46744Medium (5.4)0.50%—Nov 7, 2023
Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering…
CVE-2023-3580Medium (4.3)0.64%—Jul 10, 2023
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
CVE-2023-24278Medium (6.1)2.9%—Mar 18, 2023
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
CVE-2023-0643Medium (6.1)0.58%—Feb 2, 2023
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
CVE-2023-0642Medium (6.5)0.41%—Feb 2, 2023
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.