---
id: CVE-2021-47776
title: >-
  Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that
  allows attackers to manipulate baseUrl parameters in multiple dashboard and
  help controller endpoints
summary: >-
  Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that
  allows attackers to manipulate baseUrl parameters in multiple dashboard and
  help controller endpoints. Attackers can craft malicious requests to the
  GetContext…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-918
vendor: umbraco
product: umbraco_cms
affected:
  - umbraco_cms = 8.14.1
published: '2026-01-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:44.817'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-47776'
references:
  - url: 'https://our.umbraco.com/'
    label: disclosure@vulncheck.com
  - url: 'https://releases.umbraco.com/all-releases'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/50462'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-01-15T16:40:24.992298Z'
epss: 0.00386
epssPercentile: 0.30509
ingestedAt: '2026-10-08T16:52:14.670Z'
---

## Overview

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

## Affected

- `umbraco_cms = 8.14.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
