Vulnerabilities in Squidex
11 resultsVexday analysis
Squidex apresenta 8 vulnerabilidades catalogadas, com 4 publicadas nos últimos 90 dias, indicando atividade recente na base de código. Nenhuma vulnerabilidade está sob ataque ativo no momento, e apenas 2 atingem nível crítico, o que reduz a urgência imediata. A fraqueza dominante é CWE-918 (Server-Side Request Forgery), exigindo atenção em controles de validação de entrada e acesso a recursos internos.
CVE-2023-46253CRITICALRemote code execution in SquidexEPSS 1.5%CVE-2023-3580MEDIUMImproper Handling of Additional Special Element in squidex/squidexEPSS 0.6%CVE-2023-0643MEDIUMImproper Handling of Additional Special Element in squidex/squidexEPSS 0.6%CVE-2023-46744MEDIUMStored Cross-site Scripting in SquidexEPSS 0.5%CVE-2023-46252MEDIUMCross-Site Scripting (XSS) via postMessage Handler in SquidexEPSS 0.5%CVE-2026-24736CRITICALSquidex has Server-Side Request Forgery (SSRF) Issue in Webhook ConfigurationEPSS 0.4%CVE-2023-0642MEDIUMCross-Site Request Forgery (CSRF) in squidex/squidexEPSS 0.4%CVE-2026-41177MEDIUMSquidex has Blind SSRF via file:// Protocol in Restore API leading to Local File InteractionEPSS 0.3%CVE-2026-41170HIGHSquidex has SSRF via Backup Restore Endpoint — Admin-Controlled URL Download Allows Internal and External RequestsEPSS 0.2%CVE-2026-41172HIGHSquidex vulnerable to Server-Side Request Forgery (SSRF) via URL-based asset upload (/api/apps/{app}/assets)EPSS 0.2%CVE-2026-41171HIGHSSRF via Jint Scripting Engine HTTP Functions Due to Missing SSRF Protection on "Jint" HttpClientEPSS 0.2%