Squidex.Io develops a headless content management platform whose vulnerability profile is concentrated in its single-product line and characterized by application-layer input-handling and state-management weaknesses. The durable exposure centers on cross-site scripting, cross-site request forgery, path traversal, and improper element handling—issues typical of web-facing CMS platforms where user input and session control are broad and complex. Public exploit code has frequently materialized for vulnerabilities affecting this product; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squidex.Io over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24278MEDIUM Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability. | Mar 18, 2023 | 6.1 | 31 | NO | YES |
CVE-2026-24736HIGH Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as | Jan 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2023-46253HIGH Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows | Nov 7, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-0643MEDIUM Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | Feb 2, 2023 | 6.1 | 22 | NO | NO |
CVE-2023-0642MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0. | Feb 2, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-46252MEDIUM Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scriptin | Nov 7, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-46744MEDIUM Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authentica | Nov 7, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-46857MEDIUM Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in | Dec 7, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-3580MEDIUM Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | Jul 10, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squidex.Io.
Media articles that mention a CVE ID that affects a product developed by Squidex.Io — matched by CVE ID, not by vendor name.