Skip to main content

Vendor/product archive

umbraco / umbraco_cms CVEs

Beta · best-effort

57 CVEs tagged to umbraco / umbraco_cms4 Critical, 8 High, 40 Medium, 4 Low, 1 Unrated.

CVE-2026-46616

Published Jun 10, 2026

Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-46609

Published Jun 10, 2026

Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dia…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-31834

Published Mar 10, 2026

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticate…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-31833

Published Mar 10, 2026

Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descripti…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-31832

Published Mar 10, 2026

Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endpoint that allows authenticated…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-47776

Published Jan 15, 2026

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67288

Published Dec 22, 2025

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier be…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66625

Published Dec 9, 2025

Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-10054

Published Aug 13, 2025

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54425

Published Jul 30, 2025

Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restricted from public access where…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49147

Published Jun 24, 2025

Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request to an anonymously a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48953

Published Jun 3, 2025

Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file that doesn't adhere with…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46736

Published May 6, 2025

Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possib…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32017

Published Apr 8, 2025

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traver…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27602

Published Mar 11, 2025

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffi…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-27601

Published Mar 11, 2025

Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-55488

Published Jan 22, 2025

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been dispu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24012

Published Jan 21, 2025

Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cro…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-24011

Published Jan 21, 2025

Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-10761

Published Nov 4, 2024

A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/prev…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48929

Published Oct 22, 2024

Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7, during an explici…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48927

Published Oct 22, 2024

Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x pri…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48926

Published Oct 22, 2024

Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7,…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48925

Published Oct 22, 2024

Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-p…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2024-47819

Published Oct 22, 2024

Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and 15.0.0. This c…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 57 CVEsPage 1 of 3