VYPR

Umbraco Forms

by Umbraco

CVEs (7)

  • CVE-2021-33224CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

  • CVE-2025-68924HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

  • CVE-2026-24687MedJan 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco installations using Forms.…

  • CVE-2025-47280MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and 15.1.2, the 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any…

  • CVE-2025-23041MedJan 14, 2025
    risk 0.38cvss 5.8epss 0.00

    Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are…

  • CVE-2020-7685MedJul 28, 2020
    risk 0.35cvss 5.4epss 0.01

    This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend…

  • CVE-2024-35239LowMay 28, 2024
    risk 0.18cvss 2.7epss 0.00

    Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after…