Vulnerabilities in squidex
11 resultsVexday analysis
Squidex apresenta um perfil de risco baixo com apenas 3 vulnerabilidades registradas e nenhuma sob ataque ativo. Não há CVEs críticas e nenhuma publicação recente nos últimos 90 dias, indicando uma superfície de exposição estável. A fraqueza dominante catalogada é CWE-167, sugerindo questões de validação de entrada que requerem monitoramento, mas sem urgência imediata.
CVE-2023-46253CRITICALRemote code execution in SquidexEPSS 1.5%CVE-2023-3580MEDIUMImproper Handling of Additional Special Element in squidex/squidexEPSS 0.6%CVE-2023-0643MEDIUMImproper Handling of Additional Special Element in squidex/squidexEPSS 0.6%CVE-2023-46744MEDIUMStored Cross-site Scripting in SquidexEPSS 0.5%CVE-2023-46252MEDIUMCross-Site Scripting (XSS) via postMessage Handler in SquidexEPSS 0.5%CVE-2026-24736CRITICALSquidex has Server-Side Request Forgery (SSRF) Issue in Webhook ConfigurationEPSS 0.4%CVE-2023-0642MEDIUMCross-Site Request Forgery (CSRF) in squidex/squidexEPSS 0.4%CVE-2026-41177MEDIUMSquidex has Blind SSRF via file:// Protocol in Restore API leading to Local File InteractionEPSS 0.3%CVE-2026-41170HIGHSquidex has SSRF via Backup Restore Endpoint — Admin-Controlled URL Download Allows Internal and External RequestsEPSS 0.2%CVE-2026-41172HIGHSquidex vulnerable to Server-Side Request Forgery (SSRF) via URL-based asset upload (/api/apps/{app}/assets)EPSS 0.2%CVE-2026-41171HIGHSSRF via Jint Scripting Engine HTTP Functions Due to Missing SSRF Protection on "Jint" HttpClientEPSS 0.2%