Squidex.io

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-31016

    Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint

    Last Modified: Jul 01, 2026
    Published: Jun 29, 2026

    CVE-2026-41177

    Squidex has Blind SSRF via file:// Protocol in Restore API leading to Local File Interaction

    Last Modified: Apr 27, 2026
    Published: Apr 22, 2026

    CVE-2026-41172

    Squidex vulnerable to Server-Side Request Forgery (SSRF) via URL-based asset upload (/api/apps/{app}/assets)

    Last Modified: Apr 27, 2026
    Published: Apr 22, 2026

    CVE-2026-41171

    SSRF via Jint Scripting Engine HTTP Functions Due to Missing SSRF Protection on "Jint" HttpClient

    Last Modified: Apr 27, 2026
    Published: Apr 22, 2026

    CVE-2026-41170

    Squidex has SSRF via Backup Restore Endpoint — Admin-Controlled URL Download Allows Internal and External Requests

    Last Modified: Apr 27, 2026
    Published: Apr 22, 2026
    Items Per Page
    Squidex.io Vulnerabilities & Security CVEs | CVE-DB