Vulnerabilities > Umbraco > Umbraco CMS

DATE CVE VULNERABILITY TITLE RISK
2017-10-12 CVE-2017-15280 XXE vulnerability in Umbraco CMS
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
local
low complexity
umbraco CWE-611
5.5
2017-10-12 CVE-2017-15279 Cross-site Scripting vulnerability in Umbraco CMS
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.
network
low complexity
umbraco CWE-79
5.4
2017-04-13 CVE-2012-1301 Improper Input Validation vulnerability in Umbraco CMS 4.7.0
The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.
network
low complexity
umbraco CWE-20
critical
9.8