CVE-2019-25137
- EPSS 4.12%
- Veröffentlicht 18.05.2023 07:15:08
- Zuletzt bearbeitet 22.01.2025 17:15:08
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
CVE-2022-22690
- EPSS 1.14%
- Veröffentlicht 18.01.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:47:16
Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and the applicat...
CVE-2022-22691
- EPSS 1.02%
- Veröffentlicht 18.01.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:47:16
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers ...
CVE-2021-34254
- EPSS 0.71%
- Veröffentlicht 28.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:10:03
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
CVE-2020-5811
- EPSS 9.37%
- Veröffentlicht 30.12.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:38
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
CVE-2020-5810
- EPSS 66.2%
- Veröffentlicht 30.12.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:38
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
CVE-2020-5809
- EPSS 0.68%
- Veröffentlicht 30.12.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:38
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by defaul...
CVE-2020-29454
- EPSS 0.9%
- Veröffentlicht 02.12.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:24:02
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
CVE-2020-9472
- EPSS 2.11%
- Veröffentlicht 16.03.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:40:42
Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.
CVE-2020-9471
- EPSS 2.28%
- Veröffentlicht 16.03.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:42
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.