📦 Umbraco Forms

by Umbraco

🔍 What is Umbraco Forms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-33224

CRITICAL CVSS 9.8 Feb 24, 2023

This vulnerability allows unauthenticated attackers to upload malicious web.config and ASP files through Umbraco Forms, leading to arbitrary code execution on the server. It affects Umbraco Forms vers...

CVE-2025-68924

HIGH CVSS 7.5 Jan 16, 2026

This vulnerability allows authenticated attackers in UmbracoForms to execute arbitrary code by supplying a malicious WSDL URL as a data source. It affects all UmbracoForms installations up to version ...

CVE-2026-24687

MEDIUM CVSS 6.5 Jan 29, 2026

This vulnerability allows authenticated Umbraco backoffice users to perform path traversal attacks, enabling them to enumerate and read arbitrary files on the server filesystem. It affects Umbraco For...

CVE-2025-23041

MEDIUM CVSS 5.8 Jan 14, 2025

Umbraco.Forms has a vulnerability where character limits for form fields are only enforced client-side, not server-side. This allows attackers to bypass input validation by submitting data exceeding c...