โ† All reports

The Squidex content management system has multiple vulnerabilities prior to version 7.23.0 that allow for Server-Side Request Forgery (SSRF) attacks.

CybersecurityTechnologyConflictApr 23, 2026score 0.174 posts ยท 0 replies across 1 instances
This thread discusses multiple vulnerabilities in the Squidex content management system prior to version 7.23.0, including Blind Server-Side Request Forgery (SSRF) and SSRF vulnerabilities allowing arbitrary URL fetching. These vulnerabilities pose security risks to users and highlight the need for timely updates.

Claims

The Squidex content management system has multiple vulnerabilities prior to version 7.23.0 that allow for Server-Side Request Forgery (SSRF) attacks.
Parent: CybersecurityEntity: SquidexImpact: negativeDate: Apr 23, 2026Target: The security of the Squidex content management system prior to version 7.23.0

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-25104 ๐Ÿ“Š Score: 7.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: squidex ๐Ÿข Vendor: squidex ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functi... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25104 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25102 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: squidex ๐Ÿข Vendor: squidex ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25102 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25106 ๐Ÿ“Š Score: 7.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: squidex ๐Ÿข Vendor: squidex ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private networ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25106 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25110 ๐Ÿ“Š Score: 5.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: squidex ๐Ÿข Vendor: squidex ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25110 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability