8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.
AI Analysis
Improper Input Validation vulnerability in Progress Sitefinity web services allows remote unauthenticated attackers to compromise user account integrity and confidentiality.
Basic Information
ID
CVE-2026-7195
Source
ProgressSoftware
Published
Jun 2, 2026 at 13:04
Affected Product
Vendor
Progress Software
Product
Sitefinity
Version
14.1.0
Affected Versions
Progress Software Sitefinity 14.1.0
Progress Software Sitefinity 14.4.8100
Progress Software Sitefinity 15.0.8200
Progress Software Sitefinity 15.1.8300
Progress Software Sitefinity 15.2.8400
Progress Software Sitefinity 15.3.8500
Progress Software Sitefinity 15.4.8600
Progress Software Sitefinity 14.4.8100
Progress Software Sitefinity 15.0.8200
Progress Software Sitefinity 15.1.8300
Progress Software Sitefinity 15.2.8400
Progress Software Sitefinity 15.3.8500
Progress Software Sitefinity 15.4.8600
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Progress Software
Product
Sitefinity
Version
14.1.x, 14.2.x, 14.3.x, 14.4.x, 15.0.x, 15.1.x, 15.2.x, 15.3.x, 15.4.x