Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2023-49273
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low pr…
Umbraco Cms
8.18.10 / 10.8.1+
MEDIUM 6.5
CVE-2023-49089
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users …
Umbraco Cms
8.18.10 / 10.8.1+
MEDIUM 6.1
CVE-2023-48313
Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scr…
Umbraco Cms
10.8.1 / 12.3.4+
MEDIUM 5.4
CVE-2023-38694
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with acces…
Umbraco Cms
8.18.10 / 10.7.0+
CRITICAL 9.8
CVE-2023-37267
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerabili…
Umbraco Cms
10.6.1 / 11.4.2+
MEDIUM 5.3
CVE-2023-32312
UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integration. In affected versions …
Umbraco Identity Extensibility
after 2.0.0
HIGH 7.2
CVE-2019-25137
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to …
Umbraco Cms
after 7.15.10
CRITICAL 9.8
CVE-2021-33224
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
Umbraco Forms
Mitigation only
HIGH 7.5
CVE-2022-22690
Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to b…
Umbraco Cms
9.2.0+
HIGH 7.4
CVE-2022-22691
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It…
Umbraco Cms
9.2.0+
CRITICAL 9.8
CVE-2021-37334
Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack a…
Forms
4.4.9 / 6.0.10+
MEDIUM 6.1
CVE-2021-34254
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
Umbraco Cms
7.15.7+
MEDIUM 6.5
CVE-2020-5811EPSS 9%
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary …
Umbraco Cms
after 8.9.1
MEDIUM 5.4
CVE-2020-5809
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when ed…
Umbraco Cms
after 8.9.1
MEDIUM 5.4
CVE-2020-5810EPSS 62%
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg fi…
Umbraco Cms
after 8.9.1
HIGH 7.5
CVE-2020-7685
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file typ…
Umbraco Forms
Mitigation only
MEDIUM 6.5
CVE-2020-9472
Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.
Umbraco Cms
No fix yet
HIGH 8.8
CVE-2020-9471
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
Umbraco Cms
No fix yet
CRITICAL 9.8
CVE-2019-13957
In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.
Umbraco
Mitigation only
CRITICAL 9.8
CVE-2014-10074
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the up…
Umbraco Cms
7.2.0+
MEDIUM 5.5
CVE-2017-15280
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server o…
Umbraco Cms
after 7.7.2
MEDIUM 5.4
CVE-2017-15279
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page nam…
Umbraco Cms
after 7.7.2
CRITICAL 9.8
CVE-2012-1301
The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.
Umbraco Cms
Mitigation only
HIGH 8.8
CVE-2015-8814
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demons…
Umbraco
Patch available
HIGH 8.2
CVE-2015-8813EPSS 12%
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to con…
Umbraco
after 7.3.8
MEDIUM 6.1
CVE-2015-8815
Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before 7.4.0 allow remote attackers to inject arbitrary web script or HTML via the nam…
Umbraco
after 7.3.8
HIGH 7.5
CVE-2013-4793
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require…
Umbraco Cms
after 6.0.3