CVE Tools

Umbraco CMS

57 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Umbraco CMS, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Umbraco CMS CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Umbraco CMS CVEs per month
MonthCVEs
2024-105
2024-111
2024-120
2025-013
2025-020
2025-032
2025-041
2025-051
2025-062
2025-071
2025-081
2025-090
2025-100
2025-110
2025-122
2026-011
2026-020
2026-033
2026-040
2026-050
2026-062
2026-070
2026-080
2026-090

Severity

How the 57 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical47%
  • High814%
  • Medium4071%
  • Low47%

Latest CVEs

The 15 most recently published vulnerabilities affecting Umbraco CMS.

  1. CVE-2026-46609Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog4.6
  2. CVE-2026-46616Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers5.4
  3. CVE-2026-31834Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks7.2
  4. CVE-2026-31833Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering6.7
  5. CVE-2026-31832Umbraco Backoffice API Allows Unauthorized Modification of Domain Data5.4
  6. CVE-2021-47776Umbraco v8.14.1 - 'baseUrl' SSRF5.3
  7. CVE-2025-67288An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsi...10.0
  8. CVE-2025-66625Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality4.9
  9. CVE-2012-10054Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE9.8
  10. CVE-2025-54425Umbraco's Delivery API allows for cached requests to be returned with an invalid API key5.3
  11. CVE-2025-49147Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements5.3
  12. CVE-2025-48953Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads5.5
  13. CVE-2025-46736Umbraco Makes User Enumeration Feasible Based on Timing of Login Response5.3
  14. CVE-2025-32017Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users8.8
  15. CVE-2025-27602Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content4.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store