Progress SoftwareCVE-2026-11903
Progress Software MOVEit Transfer: cross-site scripting
High8.0CVE-2026-11903 · Published Jul 8, 2026 · updated Jul 10, 2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MOVEit Transfer Product | >= 2026.0.0, < 2026.0.1 | 2026.0.1 |
| >= 2025.1.0, < 2025.1.4 | 2025.1.4 | |
| >= 2025.0.0, < 2025.0.8 | 2025.0.8 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Path equivalence: vulnerability in Progress MOVEit Transfer | Low3.5 | 2025.1.4+1 more |
| Jul 8 | Improper Neutralization of Special Elements in Data Query Logic vulnerability... | Medium6.4 | 2025.1.3+1 more |
| Jul 8 | Progress Software MOVEit Transfer: path traversal | Medium4.5 | 2025.1.3+1 more |
| Jul 8 | Progress Software MOVEit Transfer: authentication bypass | Low3.7 | 2025.1.3+1 more |
| Jul 8 | Progress Software MOVEit Transfer: improper authorization | Low2.7 | 2025.1.3+1 more |
| Jul 8 | Improper Neutralization of Special Elements in Data Query Logic vulnerability... | High7.2 | 2025.0.8+2 more |