The Squidex content management system has multiple vulnerabilities prior to version 7.23.0 that allow for Server-Side Request Forgery (SSRF) attacks.
Claims
The Squidex content management system has multiple vulnerabilities prior to version 7.23.0 that allow for Server-Side Request Forgery (SSRF) attacks.
Parent: CybersecurityEntity: SquidexImpact: negativeDate: Apr 23, 2026Target: The security of the Squidex content management system prior to version 7.23.0
Source posts
๐จ EUVD-2026-25104
๐ Score: 7.3/10 (CVSS v3.1)
๐ฆ Product: squidex
๐ข Vendor: squidex
๐
Updated: 2026-04-22
๐ Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functi...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25104
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25102
๐ Score: 7.2/10 (CVSS v3.1)
๐ฆ Product: squidex
๐ข Vendor: squidex
๐
Updated: 2026-04-22
๐ Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25102
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25106
๐ Score: 7.3/10 (CVSS v3.1)
๐ฆ Product: squidex
๐ข Vendor: squidex
๐
Updated: 2026-04-22
๐ Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private networ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25106
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25110
๐ Score: 5.5/10 (CVSS v3.1)
๐ฆ Product: squidex
๐ข Vendor: squidex
๐
Updated: 2026-04-22
๐ Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25110
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability