Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.6 NuGet

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

GHSA-vr9v-27gg-qgx4 · CVE-2026-46609

Published · Modified

Description

Impact

Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.

Patches

This issue has been patched in 17.4.0

Ready to move

Start Securing

Free, no credit card | First findings in minutes