Medium severity5.4NVD Advisory· Published Dec 30, 2020· Updated Jun 17, 2026
CVE-2020-5809
CVE-2020-5809
Description
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
UmbracoCms.CoreNuGet | <= 8.9.1 | — |
Affected products
3- Umbraco/Umbraco CMSdescription
Patches
Vulnerability mechanics
References
3- www.tenable.com/security/research/tra-2020-59nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-95qr-67rx-9pghghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-5809ghsaADVISORY
News mentions
0No linked articles in our index yet.