CVE-2023-49278
- EPSS 0.32%
- Veröffentlicht 12.12.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:33:10
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a brute force exploit can be used to collect valid usernames. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for...
CVE-2023-49274
- EPSS 0.37%
- Veröffentlicht 12.12.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:33:09
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a user enumeration attack is possible when SMTP is not set up correctly, but reset password is enabled. Versions 8.18....
CVE-2023-49273
- EPSS 0.26%
- Veröffentlicht 12.12.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:33:09
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low privileges (Editor, etc.) are able to access some unintended endpoints. Versions 8.18.10, 10.8.1, and 1...
CVE-2023-49089
- EPSS 0.12%
- Veröffentlicht 12.12.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:32:47
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected ...
CVE-2023-48313
- EPSS 0.57%
- Veröffentlicht 12.12.2023 18:15:22
- Zuletzt bearbeitet 21.11.2024 08:31:28
Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scripting (XSS) vulnerability enabling attackers to bring malicious content into a website or applicatio...
CVE-2023-48227
- EPSS 0.11%
- Veröffentlicht 12.12.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:15
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. V...
CVE-2023-38694
- EPSS 0.49%
- Veröffentlicht 12.12.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 08:14:04
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intend...
CVE-2023-37267
- EPSS 0.39%
- Veröffentlicht 13.07.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:21
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
CVE-2019-25137
- EPSS 35.52%
- Veröffentlicht 18.05.2023 07:15:08
- Zuletzt bearbeitet 22.01.2025 17:15:08
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
CVE-2022-22690
- EPSS 0.3%
- Veröffentlicht 18.01.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:47:16
Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and the applicat...