Umbraco
8 known vulnerabilities
Top Products
Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to s
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int
Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identi
Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Sett
Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability ex
Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authent
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a
Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl par
Frequently Asked Questions
How many CVEs affect Umbraco?
Umbraco has 8 CVE records in our database, including 0 critical and 2 high severity vulnerabilities.
What are the most severe Umbraco vulnerabilities?
Umbraco has 0 critical severity (CVSS 9.0+) and 2 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Umbraco vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Umbraco products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Umbraco Vulnerabilities
CyberStrike scans your infrastructure for Umbraco vulnerabilities and provides real-time remediation guidance.
Get Started