Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Umbraco Cms MEDIUM 5.3
CVE-2021-47776

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard…

No fix yet
Fix from $1,600 2026-01-15
Umbraco Cms CRITICAL 10.0
CVE-2025-67288

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this …

Mitigation only
Fix from $2,300 2025-12-22
Umbraco Cms MEDIUM 6.5
CVE-2024-55488

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payl…

No fix yet
Fix from $1,600 2025-01-22
Umbraco Forms CRITICAL 9.8
CVE-2021-33224

File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

Mitigation only
Fix from $2,300 2023-02-24
Umbraco Forms HIGH 7.5
CVE-2020-7685

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file typ…

Mitigation only
Fix from $1,950 2020-07-28
Umbraco Cms MEDIUM 6.5
CVE-2020-9472

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

No fix yet
Fix from $1,600 2020-03-16
Umbraco Cms HIGH 8.8
CVE-2020-9471

Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

No fix yet
Fix from $1,950 2020-03-16
Umbraco CRITICAL 9.8
CVE-2019-13957

In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.

Mitigation only
Fix from $2,300 2019-10-02
Umbraco Cms CRITICAL 9.8
CVE-2012-1301

The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

Mitigation only
Fix from $2,300 2017-04-13