Umbraco Cms

Vendor:

First CVE: Dec 27, 2014 · Active for 11 years

57
Total CVEs
More Total CVEs than 99% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Umbraco Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2014
11 years ago
Most Recent CVE
Jun 10, 2026
48 days ago

CVE Severity & Scoring

Umbraco Cms57 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.8%)
Network55 (96.5%)
Unknown1 (1.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (94.7%)
High2 (3.5%)
Unknown1 (1.8%)
User Interaction
None34 (59.6%)
Unknown1 (1.8%)
Required22 (38.6%)
Privileges Required
Low24 (42.1%)
High6 (10.5%)
None26 (45.6%)
Unknown1 (1.8%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that
Aug 13, 20259.847NOYES
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS pa
Dec 30, 20205.447NONO
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier bec
Dec 22, 202510.038NONO
The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.
Apr 13, 20179.832NONO
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.
Aug 27, 20189.830NONO
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6
Jul 13, 20239.829NONO
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of
Dec 30, 20206.529NOYES
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
Mar 16, 20208.827NONO
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.as
May 18, 20237.226NONO
Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated
Mar 10, 20267.224NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Umbraco Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.5.327.72.2%00
8.2.214.31.0%00
8.14.115.30.3%00
7.12.314.80.7%00
4.7.019.83.5%00
16.3.3110.00.5%00
14.3.116.50.3%00
12.3.615.40.6%00