CVE-2026-7195: Progress Sitefinity

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.

Affected products

  • Progress Sitefinity: from 14.1.7800, before 14.4.8152 (fixed in 14.4.8152); from 15.0.8200, before 15.0.8234 (fixed in 15.0.8234); from 15.1.8300, before 15.1.8335 (fixed in 15.1.8335); from 15.2.8400, before 15.2.8441 (fixed in 15.2.8441); from 15.3.8500, before 15.3.8531 (fixed in 15.3.8531); from 15.4.8600, before 15.4.8630 (fixed in 15.4.8630)

Published 2026-06-02. Last modified 2026-07-22.