CVE-2026-92931
CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
| CWE | CWE-918 |
| Vendor | progress software |
| Product | @progress/sitefinity-nextjs-sdk |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for progress software @progress/sitefinity-nextjs-sdk
Be the first to know when new high vulnerabilities affecting progress software @progress/sitefinity-nextjs-sdk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Progress Software / @progress/sitefinity-nextjs-sdk
15.1.8326 < 15.4.8638
References
Credits
Abhishek Nandkumar Bhaskar (Abhi-Hackz)