Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Squidex.Io

First CVE: Feb 2, 2023Active for: 3 yearsTotal CVEs: 9

Squidex.Io develops a headless content management platform whose vulnerability profile is concentrated in its single-product line and characterized by application-layer input-handling and state-management weaknesses. The durable exposure centers on cross-site scripting, cross-site request forgery, path traversal, and improper element handling—issues typical of web-facing CMS platforms where user input and session control are broad and complex. Public exploit code has frequently materialized for vulnerabilities affecting this product; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Squidex.Io over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2023
3 years ago
Most Recent CVE
Jan 27, 2026
178 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-24278MEDIUM
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
Mar 18, 20236.131NOYES
CVE-2026-24736HIGH
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as
Jan 27, 20268.829NONO
CVE-2023-46253HIGH
Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows
Nov 7, 20237.223NONO
CVE-2023-0643MEDIUM
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
Feb 2, 20236.122NONO
CVE-2023-0642MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
Feb 2, 20236.522NONO
CVE-2023-46252MEDIUM
Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scriptin
Nov 7, 20236.118NONO
CVE-2023-46744MEDIUM
Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authentica
Nov 7, 20235.418NONO
CVE-2023-46857MEDIUM
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in
Dec 7, 20235.417NONO
CVE-2023-3580MEDIUM
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
Jul 10, 20234.317NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low4 (44.4%)
High1 (11.1%)
None4 (44.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Squidex.Io.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Squidex.Io — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Squidex.Io's Products

View all 3 CNAs →

Top CWEs