| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-10761 | Umbraco CMS Dashboard frame cross site scripting | Umbraco | CMS | Medium | 4.3 | 2024-11-04 05:00:07 | Deep Dive |
| CVE-2024-48929 | Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-10-22 15:54:24 | Deep Dive |
| CVE-2024-48927 | Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice | umbraco | Umbraco-CMS | Medium | 4.6 | 2024-10-22 15:50:47 | Deep Dive |
| CVE-2024-48926 | Umbraco CMS logout page displayed before session expiration | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-10-22 15:47:33 | Deep Dive |
| CVE-2024-48925 | Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API | umbraco | Umbraco-CMS | None | 0.0 | 2024-10-22 15:27:24 | Deep Dive |
| CVE-2024-47819 | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-10-22 15:25:04 | Deep Dive |
| CVE-2024-43377 | Umbraco CMS Improper Access Control vulnerability | umbraco | Umbraco-CMS | Medium | 5.4 | 2024-08-20 14:43:45 | Deep Dive |
| CVE-2024-43376 | Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information | umbraco | Umbraco-CMS | Medium | 4.3 | 2024-08-20 14:40:20 | Deep Dive |
| CVE-2024-35240 | Stored Cross-site Scripting on Print Functionality in Umbraco Commerce | umbraco | Umbraco.Commerce.Issues | Medium | 5.4 | 2024-05-28 20:15:32 | Deep Dive |
| CVE-2024-35239 | Stored Cross-site Scripting on Components of Umbraco Forms | umbraco | Umbraco.Forms.Issues | Low | 2.7 | 2024-05-28 20:15:29 | Deep Dive |
| CVE-2024-35218 | Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-05-21 13:42:27 | Deep Dive |
| CVE-2024-34071 | Open Redirect Bypass Protection | umbraco | Umbraco-CMS | Medium | 6.1 | 2024-05-21 13:31:32 | Deep Dive |
| CVE-2024-32872 | Umbraco Workflow's Backoffice users can execute arbitrary SQL | umbraco | Umbraco.Workflow.Issues | Medium | 5.5 | 2024-04-24 14:46:28 | Deep Dive |
| CVE-2024-29035 | Umbraco's Blind SSRF Leads to Port Scan by using Webhooks | umbraco | Umbraco-CMS | Medium | 4.1 | 2024-04-17 14:20:06 | Deep Dive |
| CVE-2024-28868 | Umbraco possible user enumeration vulnerability | umbraco | Umbraco-CMS | Low | 3.7 | 2024-03-20 20:07:42 | Deep Dive |
| CVE-2023-49279 | Umbraco CMS vulnerable to stored XSS via SVG File Upload | umbraco | Umbraco-CMS | Low | 3.7 | 2023-12-12 19:35:06 | Deep Dive |
| CVE-2023-49278 | Umbraco CMS brute force exploit can be used to collect valid usernames | umbraco | Umbraco-CMS | Medium | 5.3 | 2023-12-12 19:14:03 | Deep Dive |
| CVE-2023-49274 | Umbraco CMS SMTP misconfiguration exposes potential registered user email | umbraco | Umbraco-CMS | Low | 3.7 | 2023-12-12 19:10:46 | Deep Dive |
| CVE-2023-49273 | Umbraco CMS vulnerable to Privilege Escalation using Spoofing | umbraco | Umbraco-CMS | Medium | 5.4 | 2023-12-12 19:05:39 | Deep Dive |
| CVE-2023-49089 | Umbraco CMS possible path traversal when creating packages from backoffice | umbraco | Umbraco-CMS | High | 7.7 | 2023-12-12 19:02:33 | Deep Dive |