Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-32017


Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.


Published

2025-04-08T16:15:27.320

Last Modified

2025-09-22T13:56:32.683

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-23

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application umbraco umbraco_cms < 14.3.4 Yes
Application umbraco umbraco_cms < 15.3.1 Yes

References