Sitefinity
Vendor:
First CVE: Jul 3, 2017 · Active for 9 years
24
Total CVEs
More Total CVEs than 95% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sitefinity over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2017
9 years ago
Most Recent CVE
Jun 2, 2026
52 days ago
CVE Severity & Scoring
Sitefinity24 CVEs
54%
25%
21%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (58.3%)
Unknown0 (0.0%)
Required10 (41.7%)
Privileges Required
Low10 (41.7%)
High2 (8.3%)
None12 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9248CRITICAL Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK | Jul 3, 2017 | 9.8 | 96 | YES | YES |
CVE-2026-7198CRITICAL CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restric | Jun 2, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-7201HIGH CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allow | Jun 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-7195HIGH CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x be | Jun 2, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-7312HIGH CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15 | Jun 2, 2026 | 7.5 | 34 | NO | NO |
CVE-2017-15883CRITICAL Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gai | Jan 8, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-29375CRITICAL An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is poten | Apr 10, 2023 | 9.8 | 29 | NO | NO |
CVE-2017-18179HIGH Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted a | Feb 12, 2018 | 8.8 | 28 | NO | NO |
CVE-2026-7313MEDIUM CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text | Jun 2, 2026 | 4.9 | 27 | NO | NO |
CVE-2019-17392CRITICAL Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled. | Nov 26, 2019 | 9.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Sitefinity
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2 | 1 | 9.8 | 1.9% | 0 | 0 |
| 9.1 | 6 | 6.8 | 1.5% | 0 | 0 |
| 9.0 | 1 | 9.8 | 1.9% | 0 | 0 |
| 8.2 | 1 | 9.8 | 1.9% | 0 | 0 |
| 8.1 | 1 | 9.8 | 1.9% | 0 | 0 |
| 8.0 | 1 | 9.8 | 1.9% | 0 | 0 |
| 7.3 | 1 | 9.8 | 1.9% | 0 | 0 |
| 7.2 | 1 | 9.8 | 1.9% | 0 | 0 |
| 7.1 | 1 | 9.8 | 1.9% | 0 | 0 |
| 7.0 | 1 | 9.8 | 1.9% | 0 | 0 |
| 6.3 | 1 | 9.8 | 1.9% | 0 | 0 |
| 6.2 | 1 | 9.8 | 1.9% | 0 | 0 |
| 6.1 | 1 | 9.8 | 1.9% | 0 | 0 |
| 6.0 | 1 | 9.8 | 1.9% | 0 | 0 |
| 5.4 | 1 | 9.8 | 1.9% | 0 | 0 |
| 5.3 | 1 | 9.8 | 1.9% | 0 | 0 |
| 5.2 | 1 | 9.8 | 1.9% | 0 | 0 |
| 5.1 | 1 | 9.8 | 1.9% | 0 | 0 |
| 10.1 | 1 | 9.8 | 1.9% | 0 | 0 |
| 10.0 | 1 | 9.8 | 1.9% | 0 | 0 |