Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Umbraco Cms MEDIUM 5.4
CVE-2023-49273

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low pr…

Fix: 8.18.10 / 10.8.1+
Fix from $1,600 2023-12-12
Umbraco Cms MEDIUM 6.5
CVE-2023-49089

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users …

Fix: 8.18.10 / 10.8.1+
Fix from $1,600 2023-12-12
Umbraco Cms MEDIUM 6.1
CVE-2023-48313

Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scr…

Fix: 10.8.1 / 12.3.4+
Fix from $1,600 2023-12-12
Umbraco Cms MEDIUM 5.4
CVE-2023-38694

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with acces…

Fix: 8.18.10 / 10.7.0+
Fix from $1,600 2023-12-12
Umbraco Cms CRITICAL 9.8
CVE-2023-37267

Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerabili…

Fix: 10.6.1 / 11.4.2+
Fix from $2,300 2023-07-13
Umbraco Identity Extensibility MEDIUM 5.3
CVE-2023-32312

UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integration. In affected versions …

Fix: after 2.0.0
Fix from $1,600 2023-06-09
Umbraco Cms HIGH 7.2
CVE-2019-25137

Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to …

Fix: after 7.15.10
Fix from $1,950 2023-05-18
Umbraco Forms CRITICAL 9.8
CVE-2021-33224

File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

Mitigation only
Fix from $2,300 2023-02-24
Umbraco Cms HIGH 7.5
CVE-2022-22690

Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to b…

Fix: 9.2.0+
Fix from $1,950 2022-01-18
Umbraco Cms HIGH 7.4
CVE-2022-22691

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It…

Fix: 9.2.0+
Fix from $1,950 2022-01-18
Forms CRITICAL 9.8
CVE-2021-37334

Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack a…

Fix: 4.4.9 / 6.0.10+
Fix from $2,300 2021-08-25
Umbraco Cms MEDIUM 6.1
CVE-2021-34254

Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.

Fix: 7.15.7+
Fix from $1,600 2021-06-28
Umbraco Cms MEDIUM 6.5
CVE-2020-5811EPSS 9%

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary …

Fix: after 8.9.1
Fix from $1,600 2020-12-30
Umbraco Cms MEDIUM 5.4
CVE-2020-5809

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when ed…

Fix: after 8.9.1
Fix from $1,600 2020-12-30
Umbraco Cms MEDIUM 5.4
CVE-2020-5810EPSS 62%

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg fi…

Fix: after 8.9.1
Fix from $1,600 2020-12-30
Umbraco Forms HIGH 7.5
CVE-2020-7685

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file typ…

Mitigation only
Fix from $1,950 2020-07-28
Umbraco Cms MEDIUM 6.5
CVE-2020-9472

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

No fix yet
Fix from $1,600 2020-03-16
Umbraco Cms HIGH 8.8
CVE-2020-9471

Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

No fix yet
Fix from $1,950 2020-03-16
Umbraco CRITICAL 9.8
CVE-2019-13957

In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.

Mitigation only
Fix from $2,300 2019-10-02
Umbraco Cms CRITICAL 9.8
CVE-2014-10074

Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the up…

Fix: 7.2.0+
Fix from $2,300 2018-08-27
Umbraco Cms MEDIUM 5.5
CVE-2017-15280

XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server o…

Fix: after 7.7.2
Fix from $1,600 2017-10-12
Umbraco Cms MEDIUM 5.4
CVE-2017-15279

Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page nam…

Fix: after 7.7.2
Fix from $1,600 2017-10-12
Umbraco Cms CRITICAL 9.8
CVE-2012-1301

The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

Mitigation only
Fix from $2,300 2017-04-13
Umbraco HIGH 8.8
CVE-2015-8814

Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demons…

Patch available
Fix from $1,950 2017-03-03
Umbraco HIGH 8.2
CVE-2015-8813EPSS 12%

The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to con…

Fix: after 7.3.8
Fix from $1,950 2017-03-03
Umbraco MEDIUM 6.1
CVE-2015-8815

Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before 7.4.0 allow remote attackers to inject arbitrary web script or HTML via the nam…

Fix: after 7.3.8
Fix from $1,600 2017-03-03
Umbraco Cms HIGH 7.5
CVE-2013-4793

The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require…

Fix: after 6.0.3
Fix from $1,950 2014-12-27