vciy

CVEs we hold for Umbraco-cms

Records whose assigning authority named Umbraco-cms as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-69197Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansionUmbraco-CMS
CVE-2026-46616Umbraco.Cms: Open Redirect Vulnerability in Surface ControllersUmbraco-CMS
CVE-2026-46609Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialogUmbraco-CMS
CVE-2026-31834Umbraco Affected by Vertical Privilege Escalation via Missing Authorization ChecksUmbraco-CMS
CVE-2026-31833Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute FilteringUmbraco-CMS
CVE-2026-31832Umbraco Backoffice API Allows Unauthorized Modification of Domain DataUmbraco-CMS
CVE-2025-66625Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import FunctionalityUmbraco-CMS
CVE-2025-54425Umbraco's Delivery API allows for cached requests to be returned with an invalid API keyUmbraco-CMS
CVE-2025-49147Umbraco.Cms Vulnerable to Disclosure of Configured Password RequirementsUmbraco-CMS
CVE-2025-48953Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File UploadsUmbraco-CMS
CVE-2025-46736Umbraco Makes User Enumeration Feasible Based on Timing of Login ResponseUmbraco-CMS
CVE-2025-32017Umbraco has a Management API Vulnerability to Path Traversal With Authenticated UsersUmbraco-CMS
CVE-2025-27602Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized ContentUmbraco-CMS
CVE-2025-27601Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type FunctionalityUmbraco-CMS
CVE-2025-24012Umbraco Backoffice Components Have XSS/HTML Injection VulnerabilityUmbraco-CMS
CVE-2025-24011Umbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response CodesUmbraco-CMS
CVE-2024-48929Umbraco CMS Has Incomplete Server Termination During Explicit Sign-OutUmbraco-CMS
CVE-2024-48927Potential Code Execution Risk When Viewing SVG Files in Full Screen in BackofficeUmbraco-CMS
CVE-2024-48926Umbraco CMS logout page displayed before session expirationUmbraco-CMS
CVE-2024-48925Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook APIUmbraco-CMS
CVE-2024-47819Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary sectionUmbraco-CMS
CVE-2024-43377Umbraco CMS Improper Access Control vulnerabilityUmbraco-CMS
CVE-2024-43376Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive InformationUmbraco-CMS
CVE-2024-35218Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview PaneUmbraco-CMS
CVE-2024-34071Open Redirect Bypass ProtectionUmbraco-CMS
CVE-2024-29035Umbraco's Blind SSRF Leads to Port Scan by using WebhooksUmbraco-CMS
CVE-2024-28868Umbraco possible user enumeration vulnerabilityUmbraco-CMS
CVE-2023-49279Umbraco CMS vulnerable to stored XSS via SVG File UploadUmbraco-CMS
CVE-2023-49278Umbraco CMS brute force exploit can be used to collect valid usernamesUmbraco-CMS
CVE-2023-49274Umbraco CMS SMTP misconfiguration exposes potential registered user emailUmbraco-CMS
CVE-2023-49273Umbraco CMS vulnerable to Privilege Escalation using SpoofingUmbraco-CMS
CVE-2023-49089Umbraco CMS possible path traversal when creating packages from backofficeUmbraco-CMS
CVE-2023-48313Umbraco contains a DOM-XSSUmbraco-CMS
CVE-2023-48227Umbraco CMS Backoffice User can bypass "Publish" restrictionUmbraco-CMS
CVE-2023-38694Umbraco CMS vulnerable to possible injection of HTML in an unintended formUmbraco-CMS
CVE-2023-37267Umbraco allows possible Admin-level access to backoffice without Auth under rare conditionsUmbraco-CMS

36 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.