📦 Umbraco Cms

by Umbraco

🔍 What is Umbraco Cms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-67288

CRITICAL CVSS 10.0 Dec 22, 2025

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to upload malicious PDF files that can lead to remote code execution. This affects administrators who have not implemente...

CVE-2012-10054

CRITICAL CVSS 9.8 Aug 13, 2025

This vulnerability allows unauthenticated attackers to upload and execute arbitrary ASPX scripts on Umbraco CMS servers. Attackers can achieve remote code execution by exploiting a path traversal flaw...

CVE-2023-49089

HIGH CVSS 7.7 Dec 12, 2023

This vulnerability allows authenticated Umbraco backoffice users with package creation permissions to perform path traversal attacks, enabling them to write files outside intended directories. It affe...

CVE-2019-25137

HIGH CVSS 7.2 May 18, 2023

This vulnerability allows authenticated administrators in Umbraco CMS to execute arbitrary code remotely via XSLT processing. Attackers can inject malicious scripts through the xsltVisualize.aspx page...

CVE-2022-22690

HIGH CVSS 8.6 Jan 18, 2022

CVE-2022-22690 allows attackers to overwrite the UmbracoApplicationUrl configuration in Umbraco CMS, enabling them to redirect password reset and user invitation links to malicious servers. This can l...

CVE-2021-47776

MEDIUM CVSS 5.3 Jan 15, 2026

CVE-2021-47776 is a server-side request forgery (SSRF) vulnerability in Umbraco CMS that allows attackers to manipulate baseUrl parameters in dashboard and help controller endpoints. This enables unau...

CVE-2025-66625

MEDIUM CVSS 4.9 Dec 9, 2025

This vulnerability in Umbraco CMS allows attackers with backoffice access to enumerate arbitrary files on the server filesystem by exploiting predictable temporary file paths during dictionary uploads...

CVE-2025-54425

MEDIUM CVSS 5.3 Jul 30, 2025

This vulnerability allows unauthorized users to access cached content from Umbraco's Content Delivery API even when API key authentication is required. Attackers can retrieve sensitive cached response...

CVE-2025-48953

MEDIUM CVSS 5.5 Jun 3, 2025

This vulnerability allows attackers to upload files with disallowed extensions in Umbraco CMS by manipulating API requests. It affects Umbraco installations from version 14.0.0 up to (but not includin...

CVE-2025-46736

MEDIUM CVSS 5.3 May 6, 2025

This CVE describes a timing attack vulnerability in Umbraco CMS that allows attackers to determine whether specific user accounts exist by analyzing post-login API response times. This affects all Umb...

CVE-2025-27601

MEDIUM CVSS 4.3 Mar 11, 2025

An improper API access control vulnerability in Umbraco CMS allows authenticated users with low privileges to create and update data type information, which should be restricted to users with settings...

CVE-2024-55488

MEDIUM CVSS 6.5 Jan 22, 2025

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows authenticated attackers with CMS access to inject malicious scripts that execute when other users view affected content....

CVE-2025-24011

MEDIUM CVSS 5.3 Jan 21, 2025

This vulnerability in Umbraco CMS allows attackers to determine whether specific user accounts exist by analyzing response codes and timing differences in management API responses. It affects Umbraco ...

CVE-2024-48929

MEDIUM CVSS 4.2 Oct 22, 2024

This vulnerability in Umbraco CMS allows session persistence after explicit sign-out, meaning users who log out may still have active server sessions. It affects Umbraco 13.x versions before 13.5.2 an...

CVE-2024-48926

MEDIUM CVSS 4.2 Oct 22, 2024

Umbraco CMS has an insufficient session expiration vulnerability where the logout page displays a session timeout message approximately 30 seconds before the server session actually expires. This affe...

CVE-2024-47819

MEDIUM CVSS 4.2 Oct 22, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in Umbraco CMS that allows attackers to execute malicious JavaScript in the context of authenticated users. If exploited against an admini...

CVE-2024-43376

MEDIUM CVSS 4.3 Aug 20, 2024

This vulnerability in Umbraco CMS allows attackers to obtain stack trace information from Management API endpoints even when debug mode is disabled. This affects all Umbraco installations using vulner...