VendorsUmbracoumbraco_cmsall versions
Vulnerabilities

Umbraco CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2025-67288
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. The Supplier also states that PDF JavaScript runs in a completely isolated sandbox, not the browser's DOM context, which means that privilege boundaries would not be crossed, a related issue to CVE-2023-49279.
Published 2025-12-22 · Modified
10.0EPSS 0.006
CVE-2012-1301
The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.
Published 2017-04-13 · Modified
9.8EPSS 0.035
CVE-2014-10074
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.
Published 2018-08-27 · Modified
9.8EPSS 0.028
CVE-2012-10054
Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE
Published 2025-08-13 · Analyzed
9.8EPSS 0.028
CVE-2023-37267
Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Published 2023-07-13 · Modified
9.8EPSS 0.007
CVE-2020-9471
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
Published 2020-03-16 · Modified
8.8EPSS 0.023
CVE-2025-32017
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
Published 2025-04-08 · Analyzed
8.8EPSS 0.006
CVE-2024-47819
Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section
Published 2024-10-22 · Analyzed
8.7EPSS 0.003
CVE-2022-22690
Umbraco Remote ApplicationURL Overwrite
Published 2022-01-18 · Modified
8.6EPSS 0.011
CVE-2023-49089
Umbraco CMS possible path traversal when creating packages from backoffice
Published 2023-12-12 · Modified
7.7EPSS 0.006
CVE-2013-4793
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
Published 2014-12-27 · Modified
7.5EPSS 0.014
CVE-2022-22691
Umbraco Password Reset URL Poison
Published 2022-01-18 · Modified
7.4EPSS 0.010
CVE-2019-25137
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
Published 2023-05-18 · Modified
7.2EPSS 0.041
CVE-2026-31834
Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks
Published 2026-03-10 · Analyzed
7.2EPSS 0.005
CVE-2024-10761
Umbraco CMS Dashboard frame cross site scripting
Published 2024-11-04 · Modified
6.9EPSS 0.006
CVE-2021-47776
Umbraco v8.14.1 - 'baseUrl' SSRF
Published 2026-01-15 · Analyzed
6.9EPSS 0.004
CVE-2026-31833
Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering
Published 2026-03-10 · Analyzed
6.7EPSS 0.005
CVE-2020-5811
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Published 2020-12-30 · Modified
6.51 PoCEPSS 0.095
CVE-2020-9472
Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.
Published 2020-03-16 · Modified
6.5EPSS 0.021
CVE-2024-48925
Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
Published 2024-10-22 · Analyzed
6.5EPSS 0.004
CVE-2024-55488
A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.
Published 2025-01-22 · Modified
6.5EPSS 0.003
CVE-2025-48953
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Published 2025-06-03 · Analyzed
6.5EPSS 0.002
CVE-2025-27602
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Published 2025-03-11 · Analyzed
6.4EPSS 0.003
CVE-2021-34254
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
Published 2021-06-28 · Modified
6.1EPSS 0.007
CVE-2023-48313
Umbraco contains a DOM-XSS
Published 2023-12-12 · Modified
6.1EPSS 0.004
CVE-2024-34071
Open Redirect Bypass Protection
Published 2024-05-21 · Analyzed
6.1EPSS 0.004
CVE-2026-46616
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
Published 2026-06-10 · Analyzed
6.1EPSS 0.003
CVE-2017-15280
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
Published 2017-10-12 · Modified
5.5EPSS 0.011
CVE-2020-5810
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
Published 2020-12-30 · Modified
5.4EPSS 0.620
CVE-2017-15279
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.
Published 2017-10-12 · Modified
5.4EPSS 0.008
CVE-2020-5809
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
Published 2020-12-30 · Modified
5.4EPSS 0.007
CVE-2023-38694
Umbraco CMS vulnerable to possible injection of HTML in an unintended form
Published 2023-12-12 · Modified
5.4EPSS 0.004
CVE-2023-49279
Umbraco CMS vulnerable to stored XSS via SVG File Upload
Published 2023-12-12 · Modified
5.4EPSS 0.004
CVE-2023-49273
Umbraco CMS vulnerable to Privilege Escalation using Spoofing
Published 2023-12-12 · Modified
5.4EPSS 0.004
CVE-2026-31832
Umbraco Backoffice API Allows Unauthorized Modification of Domain Data
Published 2026-03-10 · Analyzed
5.4EPSS 0.003
CVE-2025-24012
Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability
Published 2025-01-21 · Analyzed
5.4EPSS 0.003
CVE-2024-43377
Umbraco CMS Improper Access Control vulnerability
Published 2024-08-20 · Analyzed
5.4EPSS 0.002
CVE-2025-24011
Umbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response Codes
Published 2025-01-21 · Analyzed
5.3EPSS 0.015
CVE-2023-49278
Umbraco CMS brute force exploit can be used to collect valid usernames
Published 2023-12-12 · Modified
5.3EPSS 0.005
CVE-2023-49274
Umbraco CMS SMTP misconfiguration exposes potential registered user email
Published 2023-12-12 · Modified
5.3EPSS 0.005
1 / 2Next →