CVE-2026-92931: Progress Software @progress/sitefinity-Nextjs-SDK
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
Affected products
- Progress Software @progress/sitefinity-Nextjs-SDK: from 15.1.8326, before 15.4.8638 (fixed in 15.4.8638)
Published 2026-10-05. Last modified 2026-10-06.