VendorsUmbracoumbraco_cmsany version
Vulnerabilities

Umbraco CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2024-35218
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Published 2024-05-21 · Analyzed
4.8EPSS 0.004
CVE-2024-48927
Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice
Published 2024-10-22 · Analyzed
4.6EPSS 0.004
CVE-2026-46609
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
Published 2026-06-10 · Analyzed
4.6EPSS 0.002
CVE-2020-29454
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
Published 2020-12-02 · Modified
4.3EPSS 0.009
CVE-2023-48227
Umbraco CMS Backoffice User can bypass "Publish" restriction
Published 2023-12-12 · Modified
4.3EPSS 0.004
CVE-2025-27601
Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Published 2025-03-11 · Analyzed
4.3EPSS 0.003
CVE-2024-48929
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Published 2024-10-22 · Analyzed
4.2EPSS 0.003
CVE-2024-48926
Umbraco CMS logout page displayed before session expiration
Published 2024-10-22 · Analyzed
4.2EPSS 0.003
← Prev2 / 2