← Back

Sitefinity

sitefinity

Vendor: Progress • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Progress
1Sitefinity
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
1Progress
1Sitefinity
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
1Progress
1Sitefinity
Nov 21, 2024
Jan 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak...Show more
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.Show less
2Progress
Telerik
2Sitefinity
Ui For Asp.net Ajax
Apr 21, 2026
Jul 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas...Show more
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.Show less