VYPR
Vendor

Umbraco

Products
9
CVEs
72
Across products
76
Status
Private

Products

9

Recent CVEs

72
View all 72 CVEs →
  • CVE-2012-10054CriAug 13, 2025
    risk 0.67cvss 9.8epss 0.03

    Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the…

  • CVE-2021-33224CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

  • CVE-2021-37334CriAug 25, 2021
    risk 0.64cvss 9.8epss 0.03

    Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has…

  • CVE-2019-13957CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.01

    In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.

  • CVE-2012-1301CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.03

    The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

  • CVE-2025-67288CriDec 22, 2025
    risk 0.58cvss 10.0epss 0.01

    An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system…

  • CVE-2020-9471HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

  • CVE-2014-10074CriAug 27, 2018
    risk 0.57cvss 9.8epss 0.03

    Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.

  • CVE-2022-22690HigJan 18, 2022
    risk 0.56cvss 8.6epss 0.01

    Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and the application builds a password reset…

  • CVE-2025-32017HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.01

    Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is…

  • CVE-2023-49089HigDec 12, 2023
    risk 0.50cvss 7.7epss 0.01

    Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location. Versions 8.18.10,…

  • CVE-2015-8814HigMar 3, 2017
    risk 0.50cvss 8.8epss 0.01

    Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.

  • CVE-2025-68924HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

  • CVE-2026-31834HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.00

    Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to…

  • CVE-2019-25137HigMay 18, 2023
    risk 0.47cvss 7.2epss 0.04

    Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.

  • CVE-2015-8813HigMar 3, 2017
    risk 0.47cvss 8.2epss 0.12

    The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.

  • CVE-2020-5811MedDec 30, 2020
    risk 0.46cvss 6.5epss 0.09

    An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

  • CVE-2026-31833MedMar 10, 2026
    risk 0.44cvss 6.7epss 0.00

    Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify…

  • CVE-2022-22691MedJan 18, 2022
    risk 0.44cvss 6.8epss 0.01

    The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the…

  • CVE-2026-24687MedJan 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco installations using Forms.…