By vendor
Progress vulnerabilities
Known CVEs affecting Progress products, prioritized by severity, with SEC.co remediation and detection guidance.
3 published vulnerabilities
- CVE-2026-7195HIGH 8.8
A flaw in Progress Sitefinity's web services allows an unauthenticated attacker to compromise user accounts—stealing login credentials and modifying account data—by exploiting improper input validation. The attack requires tricking a user into interacting with a malicious request and relies on non-standard site configuration, making it a credible but not universally threatening risk. Multiple versions from 14.1 through 15.4 are affected.
- CVE-2026-7201HIGH 8.8
A flaw in Progress Sitefinity's web services allows authenticated users to modify account properties belonging to other users, potentially compromising those accounts. An attacker with valid login credentials can exploit an authorization bypass to access and alter settings or data for accounts that should be restricted from their access level. The vulnerability requires the attacker to know certain user identifiers or properties not typically visible to standard users, which raises the bar somewhat but remains exploitable with reconnaissance.
- CVE-2026-7313HIGH 8.7
Progress Sitefinity contains a credential exposure vulnerability affecting versions 8.0.5700 through 13.3.7652. An authenticated attacker with backend administrative privileges can retrieve plaintext credentials used by Sitefinity to connect to the Sitefinity Insight analytics service. The vulnerability only manifests when Insight integration is active and non-standard site configuration is in place. While it requires existing backend access and specific preconditions, successful exploitation yields valid service account credentials that could be leveraged for lateral movement or unauthorized data access.