VendorsUmbracoumbraco_formsall versions
Vulnerabilities

Umbraco Forms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-33224
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
Published 2023-02-24 · Modified
9.8EPSS 0.007
CVE-2020-7685
Insecure Defaults
Published 2020-07-28 · Modified
7.5EPSS 0.009
CVE-2025-68924
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
Published 2026-01-16 · Analyzed
7.5EPSS 0.008
CVE-2026-24687
Umbraco.Forms has path traversal and file enumeration vulnerability in Linux/Mac
Published 2026-01-29 · Analyzed
6.5EPSS 0.004
CVE-2025-47280
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Published 2025-05-13 · Analyzed
6.1EPSS 0.003
CVE-2025-23041
Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length in Umbraco.Forms
Published 2025-01-14 · Analyzed
5.8EPSS 0.004
CVE-2024-35239
Stored Cross-site Scripting on Components of Umbraco Forms
Published 2024-05-28 · Analyzed
5.4EPSS 0.003