Showing 3 vulnerabilities on this page for sitefinity

Signals CISA KEV Ransomware Nuclei
Progress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

CWE-613Jan 7, 2025
CVSS6.8v3.1EPSS0.325%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Sitefinity 15.0 - Cross-Site Scripting (XSS)

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

CWE-79Jun 16, 2024
CVSS6.5v3.1EPSS1.3%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Potential Cross-Site Scripting (XSS) in the page editing area

Potential Cross-Site Scripting (XSS) in the page editing area.

CWE-79Feb 28, 2024
CVSS8.0v3.1EPSS0.402%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX