Moderate severityNVD Advisory· Published May 6, 2025· Updated May 6, 2025
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
CVE-2025-46736
Description
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patched in versions 10.8.10 and 13.8.1. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Umbraco.CmsNuGet | >= 11.0.0-rc1, < 13.8.1 | 13.8.1 |
Umbraco.CmsNuGet | < 10.8.10 | 10.8.10 |
Affected products
2- Range: >= 11.0.0-rc1, < 13.8.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4g8m-5mj5-c8xgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-46736ghsaADVISORY
- github.com/umbraco/Umbraco-CMS/commit/14fbd20665b453cbf094ccf4575b79a9fba07e03ghsax_refsource_MISCWEB
- github.com/umbraco/Umbraco-CMS/commit/34709be6cce9752dfa767dffbf551305f48839bcghsax_refsource_MISCWEB
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-4g8m-5mj5-c8xgghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.