CVE-2023-6784: Progress Sitefinity

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

Affected products

  • Progress Sitefinity: from 4.0, before 13.3.7648 (fixed in 13.3.7648); from 14.1, before 14.1.7828 (fixed in 14.1.7828); from 14.2, before 14.2.7932 (fixed in 14.2.7932); from 14.3, before 14.3.8029 (fixed in 14.3.8029); from 14.4, before 14.4.8133 (fixed in 14.4.8133); from 15.0, before 15.0.8223 (fixed in 15.0.8223)

Published 2023-12-20. Last modified 2026-06-17.