Launch Week Day 1: Announcing Security Design Review
nuget

Umbraco.CMS

View on nuget registry
28 Total advisories
28 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.4
NuGet

CVE-2026-46616

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

MEDIUM 4.6
NuGet

CVE-2026-46609

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

HIGH 7.2
NuGet

CVE-2026-31834

Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks

MEDIUM 6.7
NuGet

CVE-2026-31833

Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering

MEDIUM 5.4
NuGet

CVE-2026-31832

Umbraco Backoffice API Allows Unauthorized Modification of Domain Data

CRITICAL 10.0
NuGet

CVE-2025-67288

Umbraco CMS has an arbitrary file upload vulnerability

MEDIUM 4.9
NuGet

CVE-2025-66625

Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality

MEDIUM 5.3
NuGet

CVE-2025-49147

Umbraco CMS disclosure of configured password requirements

MEDIUM 5.5
NuGet

CVE-2025-48953

Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads

MEDIUM 5.3
NuGet

CVE-2025-46736

Umbraco Makes User Enumeration Feasible Based on Timing of Login Response

MEDIUM 5.3
NuGet

CVE-2025-24011

Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes

HIGH 8.8
NuGet

CVE-2025-32017

Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users

MEDIUM 4.3
NuGet

CVE-2024-10761

XSS/HTML Injection Vulnerability in Umbraco Preview Badge

NONE 0.0
NuGet

CVE-2024-48925

Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API

MEDIUM 4.6
NuGet

CVE-2024-48927

Umbraco has a Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice

MEDIUM 4.2
NuGet

CVE-2024-48926

Umbraco CMS logout page displayed before session expiration

MEDIUM 4.2
NuGet

CVE-2024-48929

Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out

MEDIUM 5.4
NuGet

CVE-2024-43377

Umbraco CMS Improper Access Control vulnerability

NONE 0.0
NuGet

CVE-2023-49279

Stored XSS via SVG File Upload

MEDIUM 4.3
NuGet

CVE-2023-48313

DOM-XSS on Backoffice login screen.

NONE 0.0
NuGet

CVE-2023-49089

Using the directory back payload (“/../”) in a package name allows placement of package in other folders.

NONE 0.0
NuGet

CVE-2023-49278

Brute force exploit can be used to collect valid usernames

NONE 0.0
NuGet

CVE-2023-38694

Possible injection of HTML into user invite mails

LOW 3.7
NuGet

CVE-2023-49274

SMTP misconfiguration leading to "Forgot Password" exploit that leaks registered user email.

MEDIUM 5.4
NuGet

CVE-2023-49273

Privilege Escalation using Spoofing

NONE 0.0
NuGet

CVE-2023-48227

Backoffice User can bypass "Publish" restriction

HIGH 8.8
NuGet

CVE-2015-8814

Umbraco CMS vulnerable to CSRF

HIGH 8.2
NuGet

CVE-2015-8813

Umbraco CMS vulnerable to CSRF

Ready to move

Start Securing

Free, no credit card | First findings in minutes