Vulnerabilities > Umbraco
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-30 | CVE-2020-5811 | Path Traversal vulnerability in Umbraco CMS An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package. | 6.5 |
2020-12-30 | CVE-2020-5810 | Cross-site Scripting vulnerability in Umbraco CMS A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. | 5.4 |
2020-12-30 | CVE-2020-5809 | Cross-site Scripting vulnerability in Umbraco CMS A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. | 5.4 |
2020-12-02 | CVE-2020-29454 | Incorrect Authorization vulnerability in Umbraco CMS Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access. | 4.3 |
2020-07-28 | CVE-2020-7685 | Insecure Default Initialization of Resource vulnerability in Umbraco Forms This affects all versions of package UmbracoForms. | 7.5 |
2020-03-16 | CVE-2020-9472 | Unrestricted Upload of File with Dangerous Type vulnerability in Umbraco CMS 8.5.3 Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality. | 6.5 |
2020-03-16 | CVE-2020-9471 | Unrestricted Upload of File with Dangerous Type vulnerability in Umbraco CMS 8.5.3 Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. | 8.8 |
2020-01-23 | CVE-2020-7210 | Cross-Site Request Forgery (CSRF) vulnerability in Umbraco CMS 8.2.2 Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. | 4.3 |
2019-10-02 | CVE-2019-13957 | SQL Injection vulnerability in Umbraco 7.3.8 In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter. | 9.8 |
2018-11-27 | CVE-2018-17256 | Cross-site Scripting vulnerability in Umbraco CMS 7.12.3 Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). | 4.8 |