umbraco has 3 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 8.7 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2025-67288Critical· 10.0An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file55CVE-2026-69197High· 8.7Umbraco is an ASP.NET CMS48GHSA-q3v2-xj35-9grxMedium· 4.9Umbraco.AI discloses sensitive application configuration values27
umbraco vulnerabilities
CVEs affecting umbraco, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-69197High· 8.7Umbraco is an ASP.NET CMS
Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node …
GHSA-q3v2-xj35-9grxMedium· 4.9Umbraco.AI discloses sensitive application configuration values
Umbraco.AI discloses sensitive application configuration values
CVE-2025-67288Critical· 10.0An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in …