MEDIUM 4.6 NuGet
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
GHSA-vr9v-27gg-qgx4 · CVE-2026-46609
Published · Modified
Description
Impact
Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.
Patches
This issue has been patched in 17.4.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes