4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether UmbracoForms is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.9
CVE-2025-68924
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
MEDIUM 5.8
CVE-2025-23041
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
NONE 0.0
CVE-2025-47280
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
HIGH 7.5
CVE-2020-7685
Insecure defaults in UmbracoForms
Browse more NuGet advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes