Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Umbraco — Vulnerabilities & Security Advisories 50

Browse all 50 CVE security advisories affecting Umbraco. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Umbraco is an open-source .NET content management system designed for building and managing digital experiences. Its architecture relies heavily on ASP.NET, making it a frequent target for web application attacks. Historically, the platform has been vulnerable to critical flaws, including Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation or insecure default configurations. Privilege escalation vulnerabilities have also been documented, allowing attackers to gain administrative access through manipulated requests. While the core framework is robust, many security incidents involve third-party packages or custom implementations that fail to adhere to secure coding standards. Recent advisories highlight the importance of keeping the CMS and its extensions updated to mitigate known risks. The high number of recorded CVEs underscores the necessity for rigorous patch management and security auditing in Umbraco deployments to prevent exploitation of these persistent weaknesses.

CVE ID Title CVSS Severity Published
CVE-2024-43376 Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information — Umbraco-CMS CWE-209 4.3 Medium 2024-08-20
CVE-2024-35240 Stored Cross-site Scripting on Print Functionality in Umbraco Commerce — Umbraco.Commerce.Issues CWE-79 5.4 Medium 2024-05-28
CVE-2024-35239 Stored Cross-site Scripting on Components of Umbraco Forms — Umbraco.Forms.Issues CWE-79 2.7 Low 2024-05-28
CVE-2024-35218 Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane — Umbraco-CMS CWE-79 4.2 Medium 2024-05-21
CVE-2024-34071 Open Redirect Bypass Protection — Umbraco-CMS CWE-601 6.1 Medium 2024-05-21
CVE-2024-32872 Umbraco Workflow's Backoffice users can execute arbitrary SQL — Umbraco.Workflow.Issues CWE-89 5.5 Medium 2024-04-24
CVE-2024-29035 Umbraco's Blind SSRF Leads to Port Scan by using Webhooks — Umbraco-CMS CWE-918 4.1 Medium 2024-04-17
CVE-2024-28868 Umbraco possible user enumeration vulnerability — Umbraco-CMS CWE-204 3.7 Low 2024-03-20
CVE-2023-49279 Umbraco CMS vulnerable to stored XSS via SVG File Upload — Umbraco-CMS CWE-79 3.7 Low 2023-12-12
CVE-2023-49278 Umbraco CMS brute force exploit can be used to collect valid usernames — Umbraco-CMS CWE-200 5.3 Medium 2023-12-12
CVE-2023-49274 Umbraco CMS SMTP misconfiguration exposes potential registered user email — Umbraco-CMS CWE-200 3.7 Low 2023-12-12
CVE-2023-49273 Umbraco CMS vulnerable to Privilege Escalation using Spoofing — Umbraco-CMS CWE-863 5.4 Medium 2023-12-12
CVE-2023-49089 Umbraco CMS possible path traversal when creating packages from backoffice — Umbraco-CMS CWE-22 7.7 High 2023-12-12
CVE-2023-48313 Umbraco contains a DOM-XSS — Umbraco-CMS CWE-79 4.3 Medium 2023-12-12
CVE-2023-48227 Umbraco CMS Backoffice User can bypass "Publish" restriction — Umbraco-CMS CWE-863 4.3 Medium 2023-12-12
CVE-2023-38694 Umbraco CMS vulnerable to possible injection of HTML in an unintended form — Umbraco-CMS CWE-79 3.5 Low 2023-12-12
CVE-2023-37267 Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions — Umbraco-CMS CWE-284 7.5 High 2023-07-13
CVE-2023-32312 Client secret not mandatory in UmbracoIdentityExtensions — UmbracoIdentityExtensions CWE-200 3.7 Low 2023-06-09
CVE-2022-22690 Umbraco Remote ApplicationURL Overwrite — Umbraco CMS 8.6 High 2022-01-18
CVE-2022-22691 Umbraco Password Reset URL Poison — Umbraco CMS CWE-640 6.8 Medium 2022-01-18

This page lists every published CVE security advisory associated with Umbraco. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.