Vulnerabilidades en umbraco

50 resultados
Análisis Vexday

Umbraco apresenta 44 vulnerabilidades catalogadas, predominantemente Cross-Site Scripting (CWE-79), sem registros de exploração ativa conhecida (KEV) ou críticos CVSS. O risco atual é moderado e estável, com apenas 2 novas vulnerabilidades identificadas nos últimos 90 dias, indicando exposição contida e sem tendência de agravamento recente.

CVE-2012-10054CRITICALUmbraco CMS < 4.7.1 codeEditorSave.asmx RCEEPSS 2.8%CVE-2025-24011MEDIUMUmbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response CodesEPSS 1.5%CVE-2022-22690HIGHUmbraco Remote ApplicationURL OverwriteEPSS 1.1%CVE-2022-22691MEDIUMUmbraco Password Reset URL PoisonEPSS 1.0%CVE-2025-68924HIGHIn Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remEPSS 0.8%CVE-2023-37267HIGHUmbraco allows possible Admin-level access to backoffice without Auth under rare conditionsEPSS 0.7%CVE-2026-69197HIGHUmbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansionEPSS 0.7%CVE-2023-32312LOWClient secret not mandatory in UmbracoIdentityExtensionsEPSS 0.6%CVE-2023-49089HIGHUmbraco CMS possible path traversal when creating packages from backofficeEPSS 0.6%CVE-2025-32017HIGHUmbraco has a Management API Vulnerability to Path Traversal With Authenticated UsersEPSS 0.6%CVE-2024-10761MEDIUMUmbraco CMS Dashboard frame cross site scriptingEPSS 0.6%CVE-2026-27449HIGHUmbraco.Engage.Forms Allows Unauthorized Access to Multiple API EndpointsEPSS 0.5%CVE-2023-49278MEDIUMUmbraco CMS brute force exploit can be used to collect valid usernamesEPSS 0.5%CVE-2026-31834HIGHUmbraco Affected by Vertical Privilege Escalation via Missing Authorization ChecksEPSS 0.5%CVE-2023-49274LOWUmbraco CMS SMTP misconfiguration exposes potential registered user emailEPSS 0.5%CVE-2026-31833MEDIUMUmbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute FilteringEPSS 0.5%CVE-2024-28868LOWUmbraco possible user enumeration vulnerabilityEPSS 0.5%CVE-2024-48927MEDIUMPotential Code Execution Risk When Viewing SVG Files in Full Screen in BackofficeEPSS 0.4%CVE-2026-24687MEDIUMUmbraco.Forms has path traversal and file enumeration vulnerability in Linux/MacEPSS 0.4%CVE-2024-29035MEDIUMUmbraco's Blind SSRF Leads to Port Scan by using WebhooksEPSS 0.4%