VendorsUmbracoumbraco_cmsall versions
Vulnerabilities

Umbraco CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2024-28868
Umbraco possible user enumeration vulnerability
Published 2024-03-20 · Analyzed
5.3EPSS 0.005
CVE-2024-29035
Umbraco's Blind SSRF Leads to Port Scan by using Webhooks
Published 2024-04-17 · Analyzed
5.3EPSS 0.004
CVE-2025-46736
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
Published 2025-05-06 · Analyzed
5.3EPSS 0.004
CVE-2024-43376
Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
Published 2024-08-20 · Analyzed
5.3EPSS 0.004
CVE-2025-49147
Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements
Published 2025-06-24 · Analyzed
5.3EPSS 0.003
CVE-2025-54425
Umbraco's Delivery API allows for cached requests to be returned with an invalid API key
Published 2025-07-30 · Analyzed
5.3EPSS 0.003
CVE-2025-66625
Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality
Published 2025-12-09 · Analyzed
4.9EPSS 0.004
CVE-2018-17256
Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vulnerability is exploited when updating or removing public access of a content.
Published 2018-11-27 · Modified
4.8EPSS 0.007
CVE-2024-35218
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Published 2024-05-21 · Analyzed
4.8EPSS 0.004
CVE-2024-48927
Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice
Published 2024-10-22 · Analyzed
4.6EPSS 0.004
CVE-2026-46609
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
Published 2026-06-10 · Analyzed
4.6EPSS 0.002
CVE-2020-7210
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
Published 2020-01-23 · Modified
4.3EPSS 0.010
CVE-2020-29454
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
Published 2020-12-02 · Modified
4.3EPSS 0.009
CVE-2023-48227
Umbraco CMS Backoffice User can bypass "Publish" restriction
Published 2023-12-12 · Modified
4.3EPSS 0.004
CVE-2025-27601
Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Published 2025-03-11 · Analyzed
4.3EPSS 0.003
CVE-2024-48929
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Published 2024-10-22 · Analyzed
4.2EPSS 0.003
CVE-2024-48926
Umbraco CMS logout page displayed before session expiration
Published 2024-10-22 · Analyzed
4.2EPSS 0.003
← Prev2 / 2