26
I Use This!
Activity Not Available
Analyzed about 1 month ago. based on code collected 3 months ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2022-22691 BDSA-2022-0144 High Jan 18, 2022 The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It m more...
8.18.15, 8.18.14, 8.18.13, 8.18.12, 8.18.11, 8.18.10, 7.15.11, 8.18.9, 8.18.8, 8.18.7
CVE-2022-22690 BDSA-2022-0152 High Jan 18, 2022 Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to bui more...
8.18.15, 8.18.14, 8.18.13, 8.18.12, 8.18.11, 8.18.10, 7.15.11, 8.18.9, 8.18.8, 8.18.7
BDSA-2025-0604 High Jan 24, 2025 A stored cross-site scripting (XSS) vulnerability in Umbraco CMS allows attackers to execute arbitrary web scripts or HTML via a crafted payload. **No more...
BDSA-2024-8040 High Nov 04, 2024 Umbraco CMS is vulnerable to cross site scripting due to a flaw in the Dashboard component, specifically the /Umbraco/preview/frame?id{} file. This cou more...
BDSA-2021-3281 High Nov 01, 2021 Umbraco is vulnerable to server side request forgery (SSRF). A remote attacker could use multiple endpoints to submit requests to the local network tha more...
BDSA-2020-3953 Low Dec 31, 2020 Umbraco content management system (CMS) contains a path traversal vulnerability during the package installation process. An attacker could exploit this more...
BDSA-2020-3952 High Dec 31, 2020 Umbraco content management system (CMS) contains a stored cross-site scripting (XSS) vulnerability due to an absence of correct parameter input validat more...
BDSA-2020-3950 High Dec 31, 2020 Umbraco CMS has a stored cross-site scripting (XSS) vulnerability due to an absence of correct parameter input validation. A remote attacker could inse more...