VYPR
Medium severity4.2NVD Advisory· Published May 21, 2024· Updated Jun 17, 2026

CVE-2024-35218

CVE-2024-35218

Description

Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. This vulnerability has been patched in version(s) 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
UmbracoCms.CoreNuGet
>= 8.0.0, < 8.18.138.18.13
UmbracoCms.CoreNuGet
>= 10.0.0, < 10.8.410.8.4
UmbracoCms.CoreNuGet
>= 12.0.0, < 12.3.712.3.7
UmbracoCms.CoreNuGet
>= 13.0.0, < 13.1.113.1.1

Affected products

3
  • cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*range: >=8.0.0,<8.18.13
    • (no CPE)range: >= 8.0.0, < 8.18.13
  • ghsa-coords
    Range: >= 8.0.0, < 8.18.13

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.