Sitefinity

Vendor:

First CVE: Jul 3, 2017 · Active for 9 years

24
Total CVEs
More Total CVEs than 95% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sitefinity over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2017
9 years ago
Most Recent CVE
Jun 2, 2026
52 days ago

CVE Severity & Scoring

Sitefinity24 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (58.3%)
Unknown0 (0.0%)
Required10 (41.7%)
Privileges Required
Low10 (41.7%)
High2 (8.3%)
None12 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK
Jul 3, 20179.896YESYES
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restric
Jun 2, 20269.840NONO
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allow
Jun 2, 20268.837NONO
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x be
Jun 2, 20268.135NONO
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15
Jun 2, 20267.534NONO
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gai
Jan 8, 20189.830NONO
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is poten
Apr 10, 20239.829NONO
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted a
Feb 12, 20188.828NONO
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text
Jun 2, 20264.927NONO
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Nov 26, 20199.827NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Sitefinity

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.219.81.9%00
9.166.81.5%00
9.019.81.9%00
8.219.81.9%00
8.119.81.9%00
8.019.81.9%00
7.319.81.9%00
7.219.81.9%00
7.119.81.9%00
7.019.81.9%00
6.319.81.9%00
6.219.81.9%00
6.119.81.9%00
6.019.81.9%00
5.419.81.9%00
5.319.81.9%00
5.219.81.9%00
5.119.81.9%00
10.119.81.9%00
10.019.81.9%00