Browse all 101 CVE security advisories affecting Progress Software Corporation. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Progress Software Corporation develops enterprise software solutions, primarily focusing on application development platforms, database management, and IoT connectivity. The company’s product portfolio, including OpenEdge and Telerik components, has historically been associated with a significant volume of security vulnerabilities, currently totaling 86 CVEs. Common flaw categories include remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation errors or improper access controls within legacy codebases. While no single catastrophic incident has defined the company’s public security history, the high CVE count suggests persistent challenges in maintaining secure coding practices across its diverse software suite. Security researchers frequently highlight these issues, urging administrators to apply patches promptly. The firm continues to address these vulnerabilities through regular updates, though the sheer number of recorded exploits indicates a complex attack surface requiring rigorous ongoing maintenance and vigilant configuration management by enterprise users.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-1968 | Progress Sitefinity 代码问题漏洞 — Sitefinity CWE-613 | 7.7 | High | 2025-04-09 |
| CVE-2024-11626 | Progress Sitefinity 安全漏洞 — Sitefinity CWE-79 | 8.4 | High | 2025-01-07 |
| CVE-2024-11625 | Progress Sitefinity 安全漏洞 — Sitefinity CWE-209 | 7.7 | High | 2025-01-07 |
| CVE-2024-4882 | URL Redirection to Arbitrary Site Exists in Sitefinity — Sitefinity CWE-601 | 6.1AI | Medium AI | 2024-07-08 |
| CVE-2024-1636 | Potential Cross-Site Scripting (XSS) in the page editing area — Sitefinity CWE-79 | 8.0 | High | 2024-02-28 |
| CVE-2024-1632 | Incorrect access control in the Sitefinity backend — Sitefinity CWE-284 | 8.8 | High | 2024-02-28 |
| CVE-2023-6784 | Potential Use of the Sitefinity System for Distribution of Phishing Emails — Sitefinity CWE-20 | 4.7 | Medium | 2023-12-20 |
This page lists every published CVE security advisory associated with Progress Software Corporation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.