Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.
2025-04-08T16:15:27.320
2025-09-22T13:56:32.683
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | umbraco | umbraco_cms | < 14.3.4 | Yes |
| Application | umbraco | umbraco_cms | < 15.3.1 | Yes |