VYPR

NuGet package

umbraco.cms.api.management

pkg:nuget/umbraco.cms.api.management

Vulnerabilities (2)

  • CVE-2025-27601Mar 11, 2025
    affected >= 15.0.0-rc1, < 15.2.3fixed 15.2.3

    Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information

  • CVE-2024-43376Aug 20, 2024
    affected >= 14.0.0, < 14.1.2fixed 14.1.2

    Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.