CVE-2025-67288 describes an arbitrary file upload vulnerability in Umbraco CMS version 16.3.3, allowing attackers to execute arbitrary code by uploading a specially crafted PDF file. This critical vulnerability, with a CVSS score of 10.0, can be exploited remotely without authentication, leading to complete compromise of confidentiality, integrity, and availability. While the vendor disputes responsibility, citing administrator configuration, the issue is gaining significant community attention with 11 mentions, though no active exploitation or public exploit code is currently reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.3.3CPE matchmatch criteria | cpe:2.3:a:umbraco:umbraco_cms:16.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.