VYPR
High severity8.8NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026

CVE-2025-32017

CVE-2025-32017

Description

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Umbraco.CmsNuGet
>= 14.0.0--preview004, < 14.3.414.3.4
Umbraco.CmsNuGet
>= 15.0.0-rc1, < 15.3.115.3.1

Affected products

3
  • cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*range: >=14.0.0,<14.3.4
    • (no CPE)range: >= 14.0.0--preview004, < 14.3.4
  • ghsa-coords
    Range: >= 14.0.0--preview004, < 14.3.4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.