Backoffice User can bypass "Publish" restriction
Modified: 9/10/2026
package
pkg:nuget/Umbraco.CMS
Backoffice User can bypass "Publish" restriction
Modified: 9/10/2026
Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
Modified: 10/22/2024
Umbraco CMS vulnerable to CSRF
Modified: 11/8/2023
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
Modified: 9/10/2026
Stored XSS via SVG File Upload
Modified: 9/10/2026
Brute force exploit can be used to collect valid usernames
Modified: 9/10/2026
SMTP misconfiguration leading to "Forgot Password" exploit that leaks registered user email.
Modified: 2/16/2024
Privilege Escalation using Spoofing
Modified: 2/16/2024
Umbraco CMS logout page displayed before session expiration
Modified: 10/22/2024
DOM-XSS on Backoffice login screen.
Modified: 9/10/2026
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Modified: 10/22/2024
Umbraco CMS vulnerable to CSRF
Modified: 11/8/2023
Possible injection of HTML into user invite mails
Modified: 2/16/2024