Umbraco / Umbraco Cms
57 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-46609 | Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog | MEDIUM | 4.6 | Jun 10, 2026 |
| CVE-2026-46616 | Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers | MEDIUM | 6.1 | Jun 10, 2026 |
| CVE-2026-31834 | Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks | HIGH | 7.2 | Mar 10, 2026 |
| CVE-2026-31833 | Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering | MEDIUM | 6.7 | Mar 10, 2026 |
| CVE-2026-31832 | Umbraco Backoffice API Allows Unauthorized Modification of Domain Data | MEDIUM | 5.4 | Mar 10, 2026 |
| CVE-2021-47776 | Umbraco v8.14.1 - 'baseUrl' SSRF | MEDIUM | 6.9 | Jan 15, 2026 |
| CVE-2025-67288 | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is dispute… | MEDIUM | 5.8 | Dec 22, 2025 |
| CVE-2025-66625 | Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality | MEDIUM | 4.9 | Dec 9, 2025 |
| CVE-2012-10054 | Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE | CRITICAL | 9.3 | Aug 13, 2025 |
| CVE-2025-54425 | Umbraco's Delivery API allows for cached requests to be returned with an invalid API key | MEDIUM | 5.3 | Jul 30, 2025 |
| CVE-2025-49147 | Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements | MEDIUM | 5.3 | Jun 24, 2025 |
| CVE-2025-48953 | Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads | MEDIUM | 6.5 | Jun 3, 2025 |
| CVE-2025-46736 | Umbraco Makes User Enumeration Feasible Based on Timing of Login Response | MEDIUM | 5.3 | May 6, 2025 |
| CVE-2025-32017 | Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users | HIGH | 8.8 | Apr 8, 2025 |
| CVE-2025-27602 | Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content | MEDIUM | 6.4 | Mar 11, 2025 |
| CVE-2025-27601 | Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality | MEDIUM | 4.3 | Mar 11, 2025 |
| CVE-2024-55488 | A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE:… | MEDIUM | 6.5 | Jan 22, 2025 |
| CVE-2025-24012 | Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability | MEDIUM | 5.4 | Jan 21, 2025 |
| CVE-2025-24011 | Umbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response Codes | MEDIUM | 5.3 | Jan 21, 2025 |
| CVE-2024-10761 | Umbraco CMS Dashboard frame cross site scripting | MEDIUM | 6.9 | Nov 4, 2024 |
| CVE-2024-48929 | Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out | MEDIUM | 4.2 | Oct 22, 2024 |
| CVE-2024-48927 | Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice | MEDIUM | 4.6 | Oct 22, 2024 |
| CVE-2024-48926 | Umbraco CMS logout page displayed before session expiration | MEDIUM | 4.2 | Oct 22, 2024 |
| CVE-2024-48925 | Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API | MEDIUM | 6.5 | Oct 22, 2024 |
| CVE-2024-47819 | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section | HIGH | 8.7 | Oct 22, 2024 |
Showing 1 to 25 of 57 CVEs