VendorsUmbracoumbraco_cmsany version
Vulnerabilities

Umbraco CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2014-10074
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.
Published 2018-08-27 · Modified
9.8EPSS 0.028
CVE-2012-10054
Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE
Published 2025-08-13 · Analyzed
9.8EPSS 0.028
CVE-2023-37267
Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Published 2023-07-13 · Modified
9.8EPSS 0.007
CVE-2025-32017
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
Published 2025-04-08 · Analyzed
8.8EPSS 0.006
CVE-2024-47819
Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section
Published 2024-10-22 · Analyzed
8.7EPSS 0.003
CVE-2022-22690
Umbraco Remote ApplicationURL Overwrite
Published 2022-01-18 · Modified
8.6EPSS 0.011
CVE-2023-49089
Umbraco CMS possible path traversal when creating packages from backoffice
Published 2023-12-12 · Modified
7.7EPSS 0.006
CVE-2013-4793
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
Published 2014-12-27 · Modified
7.5EPSS 0.014
CVE-2022-22691
Umbraco Password Reset URL Poison
Published 2022-01-18 · Modified
7.4EPSS 0.010
CVE-2019-25137
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
Published 2023-05-18 · Modified
7.2EPSS 0.041
CVE-2026-31834
Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks
Published 2026-03-10 · Analyzed
7.2EPSS 0.005
CVE-2026-31833
Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering
Published 2026-03-10 · Analyzed
6.7EPSS 0.005
CVE-2020-5811
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Published 2020-12-30 · Modified
6.51 PoCEPSS 0.095
CVE-2024-48925
Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
Published 2024-10-22 · Analyzed
6.5EPSS 0.004
CVE-2025-48953
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Published 2025-06-03 · Analyzed
6.5EPSS 0.002
CVE-2025-27602
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Published 2025-03-11 · Analyzed
6.4EPSS 0.003
CVE-2021-34254
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
Published 2021-06-28 · Modified
6.1EPSS 0.007
CVE-2023-48313
Umbraco contains a DOM-XSS
Published 2023-12-12 · Modified
6.1EPSS 0.004
CVE-2024-34071
Open Redirect Bypass Protection
Published 2024-05-21 · Analyzed
6.1EPSS 0.004
CVE-2026-46616
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
Published 2026-06-10 · Analyzed
6.1EPSS 0.003
CVE-2017-15280
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
Published 2017-10-12 · Modified
5.5EPSS 0.011
CVE-2020-5810
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
Published 2020-12-30 · Modified
5.4EPSS 0.620
CVE-2017-15279
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.
Published 2017-10-12 · Modified
5.4EPSS 0.008
CVE-2020-5809
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
Published 2020-12-30 · Modified
5.4EPSS 0.007
CVE-2023-38694
Umbraco CMS vulnerable to possible injection of HTML in an unintended form
Published 2023-12-12 · Modified
5.4EPSS 0.004
CVE-2023-49279
Umbraco CMS vulnerable to stored XSS via SVG File Upload
Published 2023-12-12 · Modified
5.4EPSS 0.004
CVE-2023-49273
Umbraco CMS vulnerable to Privilege Escalation using Spoofing
Published 2023-12-12 · Modified
5.4EPSS 0.004
CVE-2026-31832
Umbraco Backoffice API Allows Unauthorized Modification of Domain Data
Published 2026-03-10 · Analyzed
5.4EPSS 0.003
CVE-2025-24012
Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability
Published 2025-01-21 · Analyzed
5.4EPSS 0.003
CVE-2024-43377
Umbraco CMS Improper Access Control vulnerability
Published 2024-08-20 · Analyzed
5.4EPSS 0.002
CVE-2025-24011
Umbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response Codes
Published 2025-01-21 · Analyzed
5.3EPSS 0.015
CVE-2023-49278
Umbraco CMS brute force exploit can be used to collect valid usernames
Published 2023-12-12 · Modified
5.3EPSS 0.005
CVE-2023-49274
Umbraco CMS SMTP misconfiguration exposes potential registered user email
Published 2023-12-12 · Modified
5.3EPSS 0.005
CVE-2024-28868
Umbraco possible user enumeration vulnerability
Published 2024-03-20 · Analyzed
5.3EPSS 0.005
CVE-2024-29035
Umbraco's Blind SSRF Leads to Port Scan by using Webhooks
Published 2024-04-17 · Analyzed
5.3EPSS 0.004
CVE-2025-46736
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
Published 2025-05-06 · Analyzed
5.3EPSS 0.004
CVE-2024-43376
Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
Published 2024-08-20 · Analyzed
5.3EPSS 0.004
CVE-2025-54425
Umbraco's Delivery API allows for cached requests to be returned with an invalid API key
Published 2025-07-30 · Analyzed
5.3EPSS 0.003
CVE-2025-49147
Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements
Published 2025-06-24 · Analyzed
5.3EPSS 0.003
CVE-2025-66625
Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality
Published 2025-12-09 · Analyzed
4.9EPSS 0.004
1 / 2Next →