All 36 CVE vulnerabilities found in Umbraco-CMS, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities associated with Umbraco-CMS, developed by Umbraco. It collects reported flaws, primarily covering common weakness classes such as cross-site scripting, remote code execution, and SQL injection. The data spans advisories published over the past several years, reflecting the product's evolving security posture. Readers can track the vendor's advisory history, understand the prevalence of specific weakness types, and review the complete vulnerability timeline for this CMS. The entries are sourced from public CVE records, providing a centralized reference for security professionals assessing risk. No specific CVE IDs are listed in this introduction, but each record links to detailed technical information. This aggregation supports impact analysis and helps organizations prioritize patching efforts. The collection excludes low-severity issues to focus on threats with significant exploitation potential. Users can filter results by severity, date, or weakness category to narrow their research. The data is updated regularly to reflect newly disclosed vulnerabilities affecting Umbraco-CMS. This resource serves as a factual reference rather than a marketing overview, emphasizing clarity and traceability of security events.
Vendor: umbraco
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-49273 | Umbraco CMS vulnerable to Privilege Escalation using Spoofing CWE-863 | 5.4 | Medium | 2023-12-12 |
| CVE-2023-49089 | Umbraco CMS possible path traversal when creating packages from backoffice CWE-22 | 7.7 | High | 2023-12-12 |
| CVE-2023-48313 | Umbraco contains a DOM-XSS CWE-79 | 4.3 | Medium | 2023-12-12 |
| CVE-2023-48227 | Umbraco CMS Backoffice User can bypass "Publish" restriction CWE-863 | 4.3 | Medium | 2023-12-12 |
| CVE-2023-38694 | Umbraco CMS vulnerable to possible injection of HTML in an unintended form CWE-79 | 3.5 | Low | 2023-12-12 |
| CVE-2023-37267 | Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions CWE-284 | 7.5 | High | 2023-07-13 |
All 36 known CVE vulnerabilities affecting Umbraco-CMS with full Chinese analysis, references, and POCs where available.