CVE-2024-12251: Progress Telerik UI For Winui

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.

Affected products

  • Progress Telerik UI For Winui: from 2.0.0, before 3.0.0 (fixed in 3.0.0)

Published 2025-02-12. Last modified 2026-06-17.