5.8
CVE-2025-23041
- EPSS 0.15%
- Veröffentlicht 14.01.2025 19:15:44
- Zuletzt bearbeitet 19.09.2025 18:54:19
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Umbraco ≫ Umbraco Forms Version < 8.13.15
Umbraco ≫ Umbraco Forms Version >= 10.0.0 < 10.5.7
Umbraco ≫ Umbraco Forms Version >= 13.0.0 < 13.2.2
Umbraco ≫ Umbraco Forms Version >= 14.0.0 < 14.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.36 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| security-advisories@github.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.