Sitefinity
26 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Sitefinity, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Sitefinity CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 3 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 5 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High10
- Medium9
Latest CVEs
The 15 most recently published vulnerabilities affecting Sitefinity.
- CVE-2026-7313CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity8.7
- CVE-2026-7312CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity10.0
- CVE-2026-7201CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity8.8
- CVE-2026-7198CWE-284: Improper Access Control in web services in Progress Sitefinity9.8
- CVE-2026-7195CWE-20: Improper Input Validation in web services in Progress Sitefinity8.8
- CVE-2025-1968Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This iss...7.7
- CVE-2024-11627: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15...6.8
- CVE-2024-11626Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: f...8.4
- CVE-2024-11625Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, ...7.7
- CVE-2024-4882URL Redirection to Arbitrary Site Exists in Sitefinity—
- CVE-2023-27636Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.5.4
- CVE-2024-1636Potential Cross-Site Scripting (XSS) in the page editing area8.0
- CVE-2024-1632Incorrect access control in the Sitefinity backend8.8
- CVE-2023-6784Potential Use of the Sitefinity System for Distribution of Phishing Emails4.7
- CVE-2023-29375An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous ...9.8
Product grouping is registry-driven, with AI assist and human review. How it works