📦 Sitefinity

by Progress

🔍 What is Sitefinity?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-29375

CRITICAL CVSS 9.8 Apr 10, 2023

This vulnerability allows attackers to upload dangerous files through the SharePoint connector in Progress Sitefinity CMS. It affects all Sitefinity installations using vulnerable versions, potentiall...

CVE-2024-11625

HIGH CVSS 7.7 Jan 7, 2025

This CVE describes an information exposure vulnerability in Progress Software Corporation's Sitefinity CMS where error messages reveal sensitive system information. Attackers can exploit this to gathe...

CVE-2024-11626

HIGH CVSS 8.4 Jan 7, 2025

This is a cross-site scripting (XSS) vulnerability in Progress Sitefinity CMS administrative backend that allows attackers to inject malicious scripts into admin pages. It affects Sitefinity versions ...

CVE-2024-1632

HIGH CVSS 8.8 Feb 28, 2024

CVE-2024-1632 is an improper access control vulnerability in Progress Sitefinity CMS that allows low-privileged backend users to access sensitive administrative information. This affects organizations...

CVE-2024-11627

MEDIUM CVSS 6.8 Jan 7, 2025

This CVE describes a session fixation vulnerability in Progress Sitefinity CMS where session identifiers are not properly invalidated, allowing attackers to hijack user sessions. It affects Sitefinity...