| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-43377 | Umbraco CMS Improper Access Control vulnerability | umbraco | Umbraco-CMS | Medium | 5.4 | 2024-08-20 14:43:45 | Deep Dive |
| CVE-2024-43376 | Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information | umbraco | Umbraco-CMS | Medium | 4.3 | 2024-08-20 14:40:20 | Deep Dive |
| CVE-2024-35218 | Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-05-21 13:42:27 | Deep Dive |
| CVE-2024-34071 | Open Redirect Bypass Protection | umbraco | Umbraco-CMS | Medium | 6.1 | 2024-05-21 13:31:32 | Deep Dive |
| CVE-2024-29035 | Umbraco's Blind SSRF Leads to Port Scan by using Webhooks | umbraco | Umbraco-CMS | Medium | 4.1 | 2024-04-17 14:20:06 | Deep Dive |
| CVE-2024-28868 | Umbraco possible user enumeration vulnerability | umbraco | Umbraco-CMS | Low | 3.7 | 2024-03-20 20:07:42 | Deep Dive |
| CVE-2023-49279 | Umbraco CMS vulnerable to stored XSS via SVG File Upload | umbraco | Umbraco-CMS | Low | 3.7 | 2023-12-12 19:35:06 | Deep Dive |
| CVE-2023-49278 | Umbraco CMS brute force exploit can be used to collect valid usernames | umbraco | Umbraco-CMS | Medium | 5.3 | 2023-12-12 19:14:03 | Deep Dive |
| CVE-2023-49274 | Umbraco CMS SMTP misconfiguration exposes potential registered user email | umbraco | Umbraco-CMS | Low | 3.7 | 2023-12-12 19:10:46 | Deep Dive |
| CVE-2023-49273 | Umbraco CMS vulnerable to Privilege Escalation using Spoofing | umbraco | Umbraco-CMS | Medium | 5.4 | 2023-12-12 19:05:39 | Deep Dive |
| CVE-2023-49089 | Umbraco CMS possible path traversal when creating packages from backoffice | umbraco | Umbraco-CMS | High | 7.7 | 2023-12-12 19:02:33 | Deep Dive |
| CVE-2023-48313 | Umbraco contains a DOM-XSS | umbraco | Umbraco-CMS | Medium | 4.3 | 2023-12-12 17:23:49 | Deep Dive |
| CVE-2023-48227 | Umbraco CMS Backoffice User can bypass "Publish" restriction | umbraco | Umbraco-CMS | Medium | 4.3 | 2023-12-12 17:12:02 | Deep Dive |
| CVE-2023-38694 | Umbraco CMS vulnerable to possible injection of HTML in an unintended form | umbraco | Umbraco-CMS | Low | 3.5 | 2023-12-12 17:09:08 | Deep Dive |
| CVE-2023-37267 | Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions | umbraco | Umbraco-CMS | High | 7.5 | 2023-07-13 13:43:59 | Deep Dive |
| CVE-2022-22690 | Umbraco Remote ApplicationURL Overwrite | Umbraco | Umbraco CMS | High | 8.6 | 2022-01-18 16:52:22 | Deep Dive |
| CVE-2022-22691 | Umbraco Password Reset URL Poison | Umbraco | Umbraco CMS | Medium | 6.8 | 2022-01-18 16:52:20 | Deep Dive |
| CVE-2020-5809 | Umbraco 跨站脚本漏洞 | - | Umbraco CMS | 中危 | - | 2020-12-30 15:18:06 | Deep Dive |
| CVE-2020-5810 | Umbraco 跨站脚本漏洞 | - | Umbraco CMS | 中危 | - | 2020-12-30 15:18:02 | Deep Dive |
| CVE-2020-5811 | Umbraco 路径遍历漏洞 | - | Umbraco CMS | 中危 | - | 2020-12-30 15:17:57 | Deep Dive |