CVE 8.8 HIGH

CWE-20: Improper Input Validation in web services in Progress Sitefinity_CVE-2026-7195

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.

AI Analysis

Improper Input Validation vulnerability in Progress Sitefinity web services allows remote unauthenticated attackers to compromise user account integrity and confidentiality.

Basic Information

ID CVE-2026-7195
Source ProgressSoftware
Published Jun 2, 2026 at 13:04

Affected Product

Vendor Progress Software
Product Sitefinity
Version 14.1.0
Affected Versions Progress Software Sitefinity 14.1.0
Progress Software Sitefinity 14.4.8100
Progress Software Sitefinity 15.0.8200
Progress Software Sitefinity 15.1.8300
Progress Software Sitefinity 15.2.8400
Progress Software Sitefinity 15.3.8500
Progress Software Sitefinity 15.4.8600

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Progress Software
Product Sitefinity
Version 14.1.x, 14.2.x, 14.3.x, 14.4.x, 15.0.x, 15.1.x, 15.2.x, 15.3.x, 15.4.x

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.