Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.30% | — | Umbraco CMS | 10/6/2026 | 17/6/2026 | Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. This… | |
| Analizada | Media (4.6) | 0.23% | — | Umbraco CMS | 10/6/2026 | 17/6/2026 | Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0. | |
| Analizada | Alta (7.2) | 0.46% | — | Umbraco CMS | 10/3/2026 | 17/6/2026 | Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authorization enforcement… | |
| Analizada | Media (6.7) | 0.45% | — | Umbraco CMS | 10/3/2026 | 17/6/2026 | Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify instance, event handler attributes such as… | |
| Analizada | Media (5.4) | 0.29% | — | Umbraco CMS | 10/3/2026 | 17/6/2026 | Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endpoint that allows authenticated users to assign domain-related data to content nodes without proper authorization checks. The issue is caused by insufficient authorization… | |
| Analizada | Media (6.9) | 0.39% | — | Umbraco CMS | 15/1/2026 | 17/6/2026 | Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to… | |
| Modificada | Crítica (10) | 0.55% | — | Umbraco CMS | 22/12/2025 | 8/7/2026 | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco… | |
| Analizada | Media (4.9) | 0.36% | — | Umbraco CMS | 9/12/2025 | 17/6/2026 | Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to temporary file paths. The application’s error responses (HTTP 500 when a file exists,… | |
| Analizada | Crítica (9.3) | 4.0% | — | Umbraco CMS | 13/8/2025 | 16/6/2026 | Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write… | |
| Analizada | Media (5.3) | 0.34% | — | Umbraco CMS | 30/7/2025 | 17/6/2026 | Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restricted from public access where an API key must be provided in a header to authorize the request. It's also possible to configure output caching, such that the delivery API… | |
| Analizada | Media (5.3) | 0.34% | — | Umbraco CMS | 24/6/2025 | 17/6/2026 | Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request to an anonymously authenticated endpoint it's possible to retrieve information about the configured password requirements. The information available is limited… | |
| Analizada | Media (6.5) | 0.18% | — | Umbraco CMS | 3/6/2025 | 17/6/2026 | Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file that doesn't adhere with the configured allowable file extensions via a manipulated API request. The issue is patched in versions 15.4.2 and 16.0.0. No known… | |
| Analizada | Media (5.3) | 0.38% | — | Umbraco CMS | 6/5/2025 | 17/6/2026 | Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patched in versions 10.8.10 and 13.8.1. No known workarounds are available. | |
| Analizada | Alta (8.8) | 0.62% | — | Umbraco CMS | 8/4/2025 | 17/6/2026 | Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1. | |
| Analizada | Media (6.4) | 0.30% | — | Umbraco CMS | 11/3/2025 | 17/6/2026 | Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not… | |
| Analizada | Media (4.3) | 0.32% | — | Umbraco CMS | 11/3/2025 | 17/6/2026 | Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with… | |
| Modificada | Media (6.5) | 0.32% | — | Umbraco CMS | 22/1/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS.… | |
| Analizada | Media (5.4) | 0.27% | — | Umbraco CMS | 21/1/2025 | 17/6/2026 | Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch. | |
| Analizada | Media (5.3) | 1.5% | — | Umbraco CMS | 21/1/2025 | 17/6/2026 | Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account exists based on an analysis of response codes and timing of Umbraco management API responses. Versions 14.3.2 and 15.1.2 contain a patch.… | |
| Modificada | Media (6.9) | 0.57% | — | Umbraco CMS | 4/11/2024 | 17/6/2026 | A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} of the component Dashboard. The manipulation of the argument culture leads to cross site scripting. It is possible to launch… | |
| Analizada | Media (4.2) | 0.27% | — | Umbraco CMS | 22/10/2024 | 17/6/2026 | Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7, during an explicit sign-out, the server session is not fully terminated. Versions 13.5.2 and 10.8.7 contain a patch for the issue. | |
| Analizada | Media (4.6) | 0.47% | — | Umbraco CMS | 22/10/2024 | 17/6/2026 | Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode. Versions… | |
| Analizada | Baja (3.1) | 0.27% | — | Umbraco CMS | 22/10/2024 | 17/6/2026 | Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. The Backoffice displays the logout page with a session timeout message before the server session has fully… | |
| Analizada | Media (6.5) | 0.38% | — | Umbraco CMS | 22/10/2024 | 17/6/2026 | Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section.… | |
| Analizada | Alta (8.7) | 0.35% | — | Umbraco CMS | 22/10/2024 | 17/6/2026 | Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and 15.0.0. This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can… |