Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
umbraco_cms Vendor: umbraco

About This Product

umbraco_cms is a software product offered by umbraco. This product is widely deployed in production environments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The significant number of reported vulnerabilities indicates this product has received substantial security scrutiny and community focus over time. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 57 known vulnerabilities affecting umbraco umbraco_cms. This includes 4 critical-severity issues and 8 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2014 to 2026, indicating a sustained research interest and ongoing security attention. 40 medium-severity issues and 4 low-severity issues complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2013-4793 2014-12-27 2026-05-06 - 7.5 Likely
CVE-2012-1301 2017-04-13 2026-05-13 9.8 7.5 Likely
CVE-2017-15279 2017-10-12 2026-05-13 5.4 3.5 Unknown
CVE-2017-15280 2017-10-12 2026-05-13 5.5 4.3 Likely
CVE-2014-10074 2018-08-27 2024-11-21 9.8 7.5 Likely
CVE-2018-17256 2018-11-27 2024-11-21 4.8 3.5 Unknown
CVE-2020-7210 2020-01-23 2024-11-21 4.3 4.3 Likely
CVE-2020-9471 2020-03-16 2024-11-21 8.8 6.5 Likely
CVE-2020-9472 2020-03-16 2024-11-21 6.5 4.0 Likely
CVE-2020-29454 2020-12-02 2024-11-21 4.3 4.0 Likely
CVE-2020-5809 2020-12-30 2024-11-21 5.4 3.5 Unknown
CVE-2020-5810 2020-12-30 2024-11-21 5.4 3.5 Unknown
CVE-2020-5811 2020-12-30 2024-11-21 6.5 4.0 Likely
CVE-2021-34254 2021-06-28 2024-11-21 6.1 5.8 Likely
CVE-2022-22690 2022-01-18 2024-11-21 8.6 5.0 Likely
CVE-2022-22691 2022-01-18 2024-11-21 6.8 4.3 Likely
CVE-2019-25137 2023-05-18 2025-01-22 7.2 - -
CVE-2023-37267 2023-07-13 2024-11-21 7.5 - -
CVE-2023-38694 2023-12-12 2024-11-21 3.5 - -
CVE-2023-48227 2023-12-12 2024-11-21 4.3 - -
CVE-2023-48313 2023-12-12 2024-11-21 4.3 - -
CVE-2023-49089 2023-12-12 2024-11-21 7.7 - -
CVE-2023-49273 2023-12-12 2024-11-21 5.4 - -
CVE-2023-49274 2023-12-12 2024-11-21 3.7 - -
CVE-2023-49278 2023-12-12 2024-11-21 5.3 - -
CVE-2023-49279 2023-12-12 2024-11-21 3.7 - -
CVE-2024-28868 2024-03-20 2025-02-12 3.7 - -
CVE-2024-29035 2024-04-17 2025-02-12 4.1 - -
CVE-2024-34071 2024-05-21 2025-02-12 6.1 - -
CVE-2024-35218 2024-05-21 2025-02-12 4.2 - -
CVE-2024-43376 2024-08-20 2024-08-26 4.3 - -
CVE-2024-43377 2024-08-20 2024-08-26 5.4 - -
CVE-2024-47819 2024-10-22 2024-10-25 4.2 - -
CVE-2024-48925 2024-10-22 2024-10-25 0.0 - -
CVE-2024-48926 2024-10-22 2024-10-25 4.2 - -
CVE-2024-48927 2024-10-22 2024-10-25 4.6 - -
CVE-2024-48929 2024-10-22 2024-10-25 4.2 - -
CVE-2024-10761 2024-11-04 2025-01-22 4.3 5.0 Likely
CVE-2025-24011 2025-01-21 2025-02-20 5.3 - -
CVE-2025-24012 2025-01-21 2025-02-20 4.6 - -
CVE-2024-55488 2025-01-22 2025-12-31 6.5 - -
CVE-2025-27601 2025-03-11 2025-09-22 4.3 - -
CVE-2025-27602 2025-03-11 2025-09-22 4.9 - -
CVE-2025-32017 2025-04-08 2025-09-22 8.8 - -
CVE-2025-46736 2025-05-06 2025-09-03 5.3 - -
CVE-2025-48953 2025-06-03 2025-09-22 5.5 - -
CVE-2025-49147 2025-06-24 2025-09-22 5.3 - -
CVE-2025-54425 2025-07-30 2025-09-22 5.3 - -
CVE-2012-10054 2025-08-13 2025-09-19 9.8 - -
CVE-2025-66625 2025-12-09 2026-01-02 4.9 - -
CVE-2025-67288 2025-12-22 2026-01-08 10.0 - -
CVE-2021-47776 2026-01-15 2026-01-23 5.3 - -
CVE-2026-31832 2026-03-10 2026-03-18 5.4 - -
CVE-2026-31833 2026-03-10 2026-03-18 6.7 - -
CVE-2026-31834 2026-03-10 2026-03-18 7.2 - -
CVE-2026-46609 2026-06-10 2026-06-12 4.6 - -
CVE-2026-46616 2026-06-10 2026-06-12 5.4 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for umbraco umbraco_cms by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.