28 Total advisories
28 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 5.4
CVE-2026-46616
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
MEDIUM 4.6
CVE-2026-46609
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
HIGH 7.2
CVE-2026-31834
Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks
MEDIUM 6.7
CVE-2026-31833
Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering
MEDIUM 5.4
CVE-2026-31832
Umbraco Backoffice API Allows Unauthorized Modification of Domain Data
CRITICAL 10.0
CVE-2025-67288
Umbraco CMS has an arbitrary file upload vulnerability
MEDIUM 4.9
CVE-2025-66625
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality
MEDIUM 5.3
CVE-2025-49147
Umbraco CMS disclosure of configured password requirements
MEDIUM 5.5
CVE-2025-48953
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
MEDIUM 5.3
CVE-2025-46736
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
MEDIUM 5.3
CVE-2025-24011
Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes
HIGH 8.8
CVE-2025-32017
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
MEDIUM 4.3
CVE-2024-10761
XSS/HTML Injection Vulnerability in Umbraco Preview Badge
NONE 0.0
CVE-2024-48925
Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
MEDIUM 4.6
CVE-2024-48927
Umbraco has a Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice
MEDIUM 4.2
CVE-2024-48926
Umbraco CMS logout page displayed before session expiration
MEDIUM 4.2
CVE-2024-48929
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
MEDIUM 5.4
CVE-2024-43377
Umbraco CMS Improper Access Control vulnerability
NONE 0.0
CVE-2023-49279
Stored XSS via SVG File Upload
MEDIUM 4.3
CVE-2023-48313
DOM-XSS on Backoffice login screen.
NONE 0.0
CVE-2023-49089
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
NONE 0.0
CVE-2023-49278
Brute force exploit can be used to collect valid usernames
NONE 0.0
CVE-2023-38694
Possible injection of HTML into user invite mails
LOW 3.7
CVE-2023-49274
SMTP misconfiguration leading to "Forgot Password" exploit that leaks registered user email.
MEDIUM 5.4
CVE-2023-49273
Privilege Escalation using Spoofing
NONE 0.0
CVE-2023-48227
Backoffice User can bypass "Publish" restriction
HIGH 8.8
CVE-2015-8814
Umbraco CMS vulnerable to CSRF
HIGH 8.2
CVE-2015-8813
Umbraco CMS vulnerable to CSRF
Ready to move
Start Securing
Free, no credit card | First findings in minutes