Medium severity5.3NVD Advisory· Published May 6, 2025· Updated Jun 17, 2026
CVE-2025-46736
CVE-2025-46736
Description
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patched in versions 10.8.10 and 13.8.1. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Umbraco.CmsNuGet | >= 11.0.0-rc1, < 13.8.1 | 13.8.1 |
Umbraco.CmsNuGet | < 10.8.10 | 10.8.10 |
Affected products
3cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*range: <10.8.10
- (no CPE)range: >= 11.0.0-rc1, < 13.8.1
Patches
Vulnerability mechanics
References
5- github.com/umbraco/Umbraco-CMS/commit/14fbd20665b453cbf094ccf4575b79a9fba07e03nvdPatchWEB
- github.com/umbraco/Umbraco-CMS/commit/34709be6cce9752dfa767dffbf551305f48839bcnvdPatchWEB
- github.com/advisories/GHSA-4g8m-5mj5-c8xgghsaADVISORY
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-4g8m-5mj5-c8xgnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-46736ghsaADVISORY
News mentions
0No linked articles in our index yet.