Umbraco.Cms
Installs Umbraco CMS with all default dependencies in your ASP.NET Core project.
Activity
- Latest release
- 14h ago
- Total releases
- 317
- Cadence
- ~3 days
- Last 12 months
- 93
Details
- License
- MIT
- First release
- Jul 08, 2021
| Version | Released | |
|---|---|---|
13.16.2
patch
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.16.2
patch
Dependencies (6)
|
|
17.7.0-rc
pre
|
17.7.0-rc
pre
Dependencies (64)
+ 56 more |
|
18.2.0-rc
pre
|
18.2.0-rc
pre
Dependencies (65)
+ 57 more |
|
13.16.1
patch
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.16.1
patch
Dependencies (6)
|
|
18.1.1
patch
|
18.1.1
patch
Dependencies (65)
+ 57 more |
|
17.6.2
patch
|
17.6.2
patch
Dependencies (64)
+ 56 more |
|
17.6.1
patch
|
17.6.1
patch
Dependencies (64)
+ 56 more |
|
17.6.0
minor
|
17.6.0
minor
Dependencies (64)
+ 56 more |
|
18.1.0
minor
|
18.1.0
minor
Dependencies (65)
+ 57 more |
|
17.6.0-rc2
pre
|
17.6.0-rc2
pre
Dependencies (64)
+ 56 more |
|
18.1.0-rc2
pre
|
18.1.0-rc2
pre
Dependencies (65)
+ 57 more |
|
13.16.0
minor
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.16.0
minor
Dependencies (6)
|
|
18.1.0-rc
pre
|
18.1.0-rc
pre
Dependencies (65)
+ 57 more |
|
17.6.0-rc
pre
|
17.6.0-rc
pre
Dependencies (64)
+ 56 more |
|
13.16.0-rc
pre
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.16.0-rc
pre
Dependencies (6)
|
|
17.5.3
patch
|
17.5.3
patch
Dependencies (62)
+ 54 more |
|
18.0.2
patch
|
18.0.2
patch
Dependencies (63)
+ 55 more |
|
13.15.1
patch
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.15.1
patch
Dependencies (6)
|
|
17.5.2
patch
|
17.5.2
patch
Dependencies (62)
+ 54 more |
|
13.15.0
minor
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.15.0
minor
Dependencies (6)
|
|
18.0.1
patch
|
18.0.1
patch
Dependencies (63)
+ 55 more |
|
17.5.1
patch
|
17.5.1
patch
Dependencies (62)
+ 54 more |
|
18.0.0
major
|
18.0.0
major
Dependencies (63)
+ 55 more |
|
17.5.0
minor
|
17.5.0
minor
Dependencies (62)
+ 54 more |
|
18.0.0-rc3
pre
|
18.0.0-rc3
pre
Dependencies (63)
+ 55 more |
|
17.5.0-rc2
pre
|
17.5.0-rc2
pre
Dependencies (62)
+ 54 more |
|
13.15.0-rc
pre
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.15.0-rc
pre
Dependencies (6)
|
|
17.5.0-rc
pre
|
17.5.0-rc
pre
Dependencies (62)
+ 54 more |
|
18.0.0-rc2
pre
|
18.0.0-rc2
pre
Dependencies (63)
+ 55 more |
|
18.0.0-rc1
pre
|
18.0.0-rc1
pre
Dependencies (63)
+ 55 more |
|
17.4.2
patch
|
17.4.2
patch
Dependencies (62)
+ 54 more |
|
17.4.1
patch
|
17.4.1
patch
Dependencies (62)
+ 54 more |
|
17.4.0
minor
|
17.4.0
minor
Dependencies (62)
+ 54 more |
|
18.0.0-beta2
pre
|
18.0.0-beta2
pre
Dependencies (63)
+ 55 more |
|
18.0.0-beta1
pre
|
18.0.0-beta1
pre
Dependencies (63)
+ 55 more |
|
17.4.0-rc3
pre
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.4.0-rc3
pre
Dependencies (62)
+ 54 more |
|
17.4.0-rc2
pre
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.4.0-rc2
pre
Dependencies (62)
+ 54 more |
|
17.3.5
patch
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.5
patch
Dependencies (61)
+ 53 more |
|
13.14.0
minor
1 CVE
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.14.0
minor
Dependencies (6)
|
|
17.4.0-rc
pre
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.4.0-rc
pre
Dependencies (62)
+ 54 more |
|
13.14.0-rc3
pre
2 CVEs
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.14.0-rc3
pre
Dependencies (6)
|
|
13.14.0-rc2
pre
2 CVEs
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.14.0-rc2
pre
Dependencies (6)
|
|
17.3.4
patch
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.4
patch
Dependencies (61)
+ 53 more |
|
13.14.0-rc
pre
2 CVEs
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2025-67288
GHSA-54mj-vcvj-q3v5
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Medium
Network
Low
None
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides hooks to perform file validation, it does not do implement filtering by default. Users are expected to implement their own validation. Note: This vulnerability is disputed by Ubraco. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 243 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.15.0
13.15.0-rc
13.15.1
13.16.0
13.16.0-rc
13.16.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
14.0.0
14.0.0-rc1
14.0.0-rc2
14.0.0-rc3
14.0.0-rc4
14.0.0-rc5
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
13.14.0-rc
pre
Dependencies (6)
|
|
17.3.3
patch
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.3
patch
Dependencies (61)
+ 53 more |
|
17.3.2
patch
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.2
patch
Dependencies (61)
+ 53 more |
|
17.3.1
patch
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.1
patch
Dependencies (61)
+ 53 more |
|
17.3.0
minor
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.0
minor
Dependencies (61)
+ 53 more |
|
17.3.0-rc3
pre
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.0-rc3
pre
Dependencies (61)
+ 53 more |
|
17.3.0-rc2
pre
2 CVEs
CVE-2026-46609
GHSA-vr9v-27gg-qgx4
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactAuthenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding. PatchesThis issue has been patched in 17.4.0 Affected versions
14.0.0
14.1.0
14.1.0-rc
14.1.0-rc2
14.1.1
14.1.2
14.2.0
14.2.0-rc
14.2.0-rc2
14.2.0-rc3
14.3.0
14.3.0-rc
+ 86 more Show less
14.3.1
14.3.2
14.3.3
14.3.4
15.0.0
15.0.0-rc1
15.0.0-rc2
15.0.0-rc3
15.0.0-rc4
15.1.0
15.1.0-rc
15.1.0-rc2
15.1.1
15.1.2
15.2.0
15.2.0-rc
15.2.1
15.2.2
15.2.3
15.3.0
15.3.0-rc
15.3.0-rc2
15.3.1
15.4.0
15.4.0-rc
15.4.0-rc2
15.4.1
15.4.2
15.4.3
15.4.4
16.0.0
16.0.0-rc
16.0.0-rc2
16.0.0-rc3
16.0.0-rc4
16.0.0-rc5
16.0.0-rc6
16.1.0
16.1.0-rc
16.1.1
16.2.0
16.2.0-rc
16.2.0-rc2
16.3.0
16.3.0-rc
16.3.0-rc2
16.3.0-rc3
16.3.0-rc4
16.3.1
16.3.2
16.3.3
16.3.4
16.4.0
16.4.0-rc
16.4.0-rc2
16.4.1
16.5.0
16.5.0-rc
16.5.1
17.0.0
17.0.0-beta
17.0.0-rc1
17.0.0-rc2
17.0.0-rc3
17.0.0-rc4
17.0.1
17.0.2
17.1.0
17.1.0-rc
17.2.0
17.2.0-rc
17.2.0-rc2
17.2.1
17.2.2
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-46616
GHSA-2qjj-h6wp-c7h7
May 21, 2026
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
ImpactSome of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. PatchesThe issue is resolved in versions 17.4.0 and 13.14.0. WorkaroundsIf users cannot upgrade immediately, they can mitigate the issue in their own site by ensuring every Razor form that posts to For example:
Resourceshttps://github.com/umbraco/Umbraco-CMS/pull/22565 https://github.com/umbraco/Umbraco-CMS/pull/22561 Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 180 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.10
10.8.11
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
10.8.9
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.10.0
13.10.0-rc
13.10.1
13.11.0
13.11.0-rc
13.11.0-rc2
13.12.0
13.12.0-rc
13.12.0-rc2
13.12.1
13.13.0
13.13.0-rc
13.13.0-rc2
13.13.0-rc3
13.13.1
13.14.0-rc
13.14.0-rc2
13.14.0-rc3
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
13.7.1
13.7.2
13.8.0
13.8.0-rc
13.8.1
13.9.0
13.9.0-rc
13.9.1
13.9.2
13.9.3
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
17.3.0
17.3.0-rc
17.3.0-rc2
17.3.0-rc3
17.3.1
17.3.2
17.3.3
17.3.4
17.3.5
17.4.0-rc
17.4.0-rc2
17.4.0-rc3
Fixed in
13.14.0
17.4.0
References Updated Jun 10, 2026 · Source: OSV.dev |
17.3.0-rc2
pre
Dependencies (61)
+ 53 more |