Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Umbraco — Vulnerabilities & Security Advisories 50

Browse all 50 CVE security advisories affecting Umbraco. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Umbraco is an open-source .NET content management system designed for building and managing digital experiences. Its architecture relies heavily on ASP.NET, making it a frequent target for web application attacks. Historically, the platform has been vulnerable to critical flaws, including Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation or insecure default configurations. Privilege escalation vulnerabilities have also been documented, allowing attackers to gain administrative access through manipulated requests. While the core framework is robust, many security incidents involve third-party packages or custom implementations that fail to adhere to secure coding standards. Recent advisories highlight the importance of keeping the CMS and its extensions updated to mitigate known risks. The high number of recorded CVEs underscores the necessity for rigorous patch management and security auditing in Umbraco deployments to prevent exploitation of these persistent weaknesses.

CVE ID Title CVSS Severity Published
CVE-2026-69197 Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion — Umbraco-CMS CWE-200 8.7 High 2026-09-17
CVE-2026-46609 Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog — Umbraco-CMS CWE-79 4.6 Medium 2026-06-10
CVE-2026-46616 Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers — Umbraco-CMS CWE-601 5.4 Medium 2026-06-10
CVE-2026-31834 Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks — Umbraco-CMS CWE-269 7.2 High 2026-03-10
CVE-2026-31833 Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering — Umbraco-CMS CWE-79 6.7 Medium 2026-03-10
CVE-2026-31832 Umbraco Backoffice API Allows Unauthorized Modification of Domain Data — Umbraco-CMS CWE-639 5.4 Medium 2026-03-10
CVE-2026-27449 Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints — Umbraco.Engage.Forms CWE-284 7.5 High 2026-02-26
CVE-2026-24687 Umbraco.Forms has path traversal and file enumeration vulnerability in Linux/Mac — Umbraco.Forms.Issues CWE-22 4.9AI Medium AI 2026-01-29
CVE-2025-68924 Umbraco Forms 安全漏洞 — Forms CWE-829 7.5 High 2026-01-16
CVE-2021-47776 Umbraco v8.14.1 - 'baseUrl' SSRF — Umbraco CWE-918 5.3 Medium 2026-01-15
CVE-2025-66625 Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality — Umbraco-CMS CWE-200 4.9 Medium 2025-12-09
CVE-2012-10054 Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE — CMS CWE-434 9.8AI Critical AI 2025-08-13
CVE-2025-54425 Umbraco's Delivery API allows for cached requests to be returned with an invalid API key — Umbraco-CMS CWE-200 5.3 Medium 2025-07-30
CVE-2025-49147 Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements — Umbraco-CMS CWE-497 5.3 Medium 2025-06-24
CVE-2025-48953 Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads — Umbraco-CMS CWE-434 5.5 Medium 2025-06-03
CVE-2025-47280 Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow — Umbraco.Forms.Issues CWE-116 4.7AI Medium AI 2025-05-13
CVE-2025-46736 Umbraco Makes User Enumeration Feasible Based on Timing of Login Response — Umbraco-CMS CWE-204 5.3 Medium 2025-05-06
CVE-2025-32017 Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users — Umbraco-CMS CWE-23 8.8 High 2025-04-08
CVE-2025-27602 Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content — Umbraco-CMS CWE-285 4.9 Medium 2025-03-11
CVE-2025-27601 Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality — Umbraco-CMS CWE-285 4.3 Medium 2025-03-11
CVE-2025-24012 Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability — Umbraco-CMS CWE-79 4.6 Medium 2025-01-21
CVE-2025-24011 Umbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response Codes — Umbraco-CMS CWE-200 5.3 Medium 2025-01-21
CVE-2025-23041 Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length in Umbraco.Forms — Umbraco.Forms.Issues CWE-20 5.8 Medium 2025-01-14
CVE-2024-10761 Umbraco CMS Dashboard frame cross site scripting — CMS CWE-79 4.3 Medium 2024-11-04
CVE-2024-48929 Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out — Umbraco-CMS CWE-384 4.2 Medium 2024-10-22
CVE-2024-48927 Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice — Umbraco-CMS CWE-74 4.6 Medium 2024-10-22
CVE-2024-48926 Umbraco CMS logout page displayed before session expiration — Umbraco-CMS CWE-613 4.2 Medium 2024-10-22
CVE-2024-48925 Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API — Umbraco-CMS CWE-284 - - 2024-10-22
CVE-2024-47819 Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section — Umbraco-CMS CWE-79 4.2 Medium 2024-10-22
CVE-2024-43377 Umbraco CMS Improper Access Control vulnerability — Umbraco-CMS CWE-284 5.4 Medium 2024-08-20

This page lists every published CVE security advisory associated with Umbraco. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.