CVE Explorer
CVE-2026-7312
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuration.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Sitefinity","vendor":"Progress Software","versions":[{"lessThan":"14.4.8152","status":"affected","version":"14.0.7700","versionType":"custom"},{"lessThan":"15.0.8234","status":"affected","version":"15.0.8200","versionType":"custom"},{"lessThan":"15.1.8335","status":"affected","version":"15.1.8300","versionType":"custom"},{"lessThan":"15.2.8441","status":"affected","version":"15.2.8400","versionType":"custom"},{"lessThan":"15.3.8531","status":"affected","version":"15.3.8500","versionType":"custom"},{"lessThan":"15.4.8630","status":"affected","version":"1…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8ac0b9ef7c5c5f3c10f767353a2458cde5a891649b97bb8ca9d36b7edd5e1770 · sha256:174b5b26387b0d0e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8ac0b9ef7c5c5f3c10f767353a2458cde5a891649b97bb8ca9d36b7edd5e1770 · sha256:174b5b26387b0d0e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE‑522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8ac0b9ef7c5c5f3c10f767353a2458cde5a891649b97bb8ca9d36b7edd5e1770 · sha256:174b5b26387b0d0e… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8ac0b9ef7c5c5f3c10f767353a2458cde5a891649b97bb8ca9d36b7edd5e1770 · sha256:174b5b26387b0d0e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.