CVE-2025-1968

Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from 15.0 before 15.0.8231, from 15.1 before 15.1.8332, from 15.2 before 15.2.8429.


We have discovered 977 live websites that are affected by CVE-2025-1968.

Run a Free Instant Scan




Affected Software

Product  Sitefinity
Category Content Management System
Vulnerable Domains977 live websites (26% of Sitefinity install base)
Vulnerable Versions
  • from 14 through 14.3
  • from 14.4 through 14.4.8145
  • from 15 through 15.0.8231
  • from 15.1 through 15.1.8332
  • from 15.2 through 15.2.8429
Vulnerable Versions Count66 versions ( 28% of all versions)


Common Weakness Enumeration

CWE-613 Insufficient Session Expiration



Details

  • Published - Apr 9, 2025
  • Updated - May 2, 2025

Website Distribution by Country

Number of websites using CVE-2025-1968
United States748 websites



Canada46 websites
Saudi Arabia35 websites
GB17 websites
Singapore14 websites
Australia12 websites
Italy12 websites
Chile11 websites
United Arab Emirates9 websites
Netherlands9 websites

Website Distribution by TLD

Number of websites using CVE-2025-1968
.com517 websites
.org186 websites
.ca37 websites
.com.au17 websites
.net13 websites
.it12 websites
.edu12 websites
.nl10 websites
.co.uk10 websites
.cn3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-1968

Top websites that are affected by CVE-2025-1968. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States*,***
*******.***.gov United States**,***
************.com United States**,***
*****.org United States**,***
*****.********.gov United States**,***
****.gov United States**,***
****.****.it Italy**,***
********.com United States**,***
***.********.gov United States**,***
***********.org United States**,***
See full domain list

FAQ

CVE-2025-1968 is Insufficient Session Expiration in Sitefinity
A total of 977 websites have been identified as vulnerable to CVE-2025-1968, based on global website indexing conducted by WebTechSurvey.
The Sitefinity is affected by the CVE-2025-1968 vulnerability.
Sitefinity versions up to 15.2.8429 are vulnerable to CVE-2025-1968.
CVE-2025-1968 is resolved in version 15.2.8429 of Sitefinity.