Moderate severityNVD Advisory· Published Jan 21, 2025· Updated Feb 12, 2025
Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability
CVE-2025-24012
Description
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Umbraco.Cms.StaticAssetsNuGet | >= 14.0.0, < 14.3.2 | 14.3.2 |
Umbraco.Cms.StaticAssetsNuGet | >= 15.0.0, < 15.1.2 | 15.1.2 |
@umbraco-cms/backofficenpm | >= 14.0.0, < 14.3.2 | 14.3.2 |
@umbraco-cms/backofficenpm | >= 15.0.0, < 15.1.2 | 15.1.2 |
Affected products
3- ghsa-coords2 versions
>= 14.0.0, < 14.3.2+ 1 more
- (no CPE)range: >= 14.0.0, < 14.3.2
- (no CPE)range: >= 14.0.0, < 14.3.2
- Range: >= 14.0.0, < 14.3.2
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-wv8v-rmw2-25wcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-24012ghsaADVISORY
- github.com/umbraco/Umbraco-CMS/commit/d4f8754f933895b3a329296e25ddea6f84a0aea2ghsax_refsource_MISCWEB
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wv8v-rmw2-25wcghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.