← Back

CVE-2026-7195

nvd nist
Published: Jun 2, 2026Modified: Jul 22, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.

Affected (6)

Products: Progress: Sitefinity
1 product
Sitefinity
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Progress
From 14.1.7800 to 14.4.8152
From 15.0.8200 to 15.0.8234
From 15.1.8300 to 15.1.8335
From 15.2.8400 to 15.2.8441
From 15.3.8500 to 15.3.8531
From 15.4.8600 to 15.4.8630

Timeline

No history available yet.