Umbraco Cms
Vendor:
First CVE: Dec 27, 2014 · Active for 11 years
57
Total CVEs
More Total CVEs than 99% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Umbraco Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2014
11 years ago
Most Recent CVE
Jun 10, 2026
48 days ago
CVE Severity & Scoring
Umbraco Cms57 CVEs
75%
14%
9%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.8%)
Network55 (96.5%)
Unknown1 (1.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (94.7%)
High2 (3.5%)
Unknown1 (1.8%)
User Interaction
None34 (59.6%)
Unknown1 (1.8%)
Required22 (38.6%)
Privileges Required
Low24 (42.1%)
High6 (10.5%)
None26 (45.6%)
Unknown1 (1.8%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-10054CRITICAL Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that | Aug 13, 2025 | 9.8 | 47 | NO | YES |
CVE-2020-5810MEDIUM A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS pa | Dec 30, 2020 | 5.4 | 47 | NO | NO |
CVE-2025-67288CRITICAL An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier bec | Dec 22, 2025 | 10.0 | 38 | NO | NO |
CVE-2012-1301CRITICAL The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter. | Apr 13, 2017 | 9.8 | 32 | NO | NO |
CVE-2014-10074CRITICAL Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files. | Aug 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-37267CRITICAL Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6 | Jul 13, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-5811MEDIUM An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of | Dec 30, 2020 | 6.5 | 29 | NO | YES |
CVE-2020-9471HIGH Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. | Mar 16, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-25137HIGH Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.as | May 18, 2023 | 7.2 | 26 | NO | NO |
CVE-2026-31834HIGH Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated | Mar 10, 2026 | 7.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Umbraco Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.5.3 | 2 | 7.7 | 2.2% | 0 | 0 |
| 8.2.2 | 1 | 4.3 | 1.0% | 0 | 0 |
| 8.14.1 | 1 | 5.3 | 0.3% | 0 | 0 |
| 7.12.3 | 1 | 4.8 | 0.7% | 0 | 0 |
| 4.7.0 | 1 | 9.8 | 3.5% | 0 | 0 |
| 16.3.3 | 1 | 10.0 | 0.5% | 0 | 0 |
| 14.3.1 | 1 | 6.5 | 0.3% | 0 | 0 |
| 12.3.6 | 1 | 5.4 | 0.6% | 0 | 0 |