Umbraco.Cms.Web.BackOffice
Contains the backoffice assembly needed to run the backend of Umbraco CMS.
Activity
- Latest release
- 10h ago
- Total releases
- 187
- Cadence
- ~9 days
- Last 12 months
- 22
Details
- License
- MIT
- First release
- Jul 08, 2021
| Version | Released | |
|---|---|---|
13.16.2
patch
|
13.16.2
patch
Dependencies (3)
|
|
13.16.1
patch
|
13.16.1
patch
Dependencies (3)
|
|
13.16.0
minor
|
13.16.0
minor
Dependencies (3)
|
|
13.16.0-rc
pre
|
13.16.0-rc
pre
Dependencies (3)
|
|
13.15.1
patch
|
13.15.1
patch
Dependencies (3)
|
|
13.15.0
minor
|
13.15.0
minor
Dependencies (3)
|
|
13.15.0-rc
pre
|
13.15.0-rc
pre
Dependencies (3)
|
|
13.14.0
minor
|
13.14.0
minor
Dependencies (3)
|
|
13.14.0-rc3
pre
|
13.14.0-rc3
pre
Dependencies (3)
|
|
13.14.0-rc2
pre
|
13.14.0-rc2
pre
Dependencies (3)
|
|
13.14.0-rc
pre
|
13.14.0-rc
pre
Dependencies (3)
|
|
13.13.1
patch
|
13.13.1
patch
Dependencies (3)
|
|
13.13.0
minor
|
13.13.0
minor
Dependencies (3)
|
|
13.13.0-rc3
pre
|
13.13.0-rc3
pre
Dependencies (3)
|
|
13.13.0-rc2
pre
|
13.13.0-rc2
pre
Dependencies (3)
|
|
13.12.1
patch
|
13.12.1
patch
Dependencies (3)
|
|
13.13.0-rc
pre
|
13.13.0-rc
pre
Dependencies (3)
|
|
13.12.0
minor
|
13.12.0
minor
Dependencies (3)
|
|
13.12.0-rc2
pre
|
13.12.0-rc2
pre
Dependencies (3)
|
|
13.12.0-rc
pre
|
13.12.0-rc
pre
Dependencies (3)
|
|
13.11.0
minor
|
13.11.0
minor
Dependencies (3)
|
|
13.11.0-rc2
pre
|
13.11.0-rc2
pre
Dependencies (3)
|
|
13.11.0-rc
pre
|
13.11.0-rc
pre
Dependencies (3)
|
|
13.10.1
patch
|
13.10.1
patch
Dependencies (3)
|
|
13.10.0
minor
|
13.10.0
minor
Dependencies (3)
|
|
13.10.0-rc
pre
|
13.10.0-rc
pre
Dependencies (3)
|
|
13.9.3
patch
|
13.9.3
patch
Dependencies (3)
|
|
13.9.2
patch
|
13.9.2
patch
Dependencies (3)
|
|
10.8.11
patch
|
10.8.11
patch
Dependencies (6)
|
|
13.9.1
patch
|
13.9.1
patch
Dependencies (3)
|
|
13.9.0
minor
|
13.9.0
minor
Dependencies (3)
|
|
13.9.0-rc
pre
|
13.9.0-rc
pre
Dependencies (3)
|
|
13.8.1
patch
|
13.8.1
patch
Dependencies (3)
|
|
10.8.10
patch
|
10.8.10
patch
Dependencies (6)
|
|
13.8.0
minor
|
13.8.0
minor
Dependencies (3)
|
|
13.8.0-rc
pre
|
13.8.0-rc
pre
Dependencies (3)
|
|
13.7.2
patch
|
13.7.2
patch
Dependencies (3)
|
|
13.7.1
patch
|
13.7.1
patch
Dependencies (3)
|
|
10.8.9
patch
|
10.8.9
patch
Dependencies (6)
|
|
13.7.0
minor
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.7.0
minor
Dependencies (3)
|
|
13.7.0-rc
pre
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.7.0-rc
pre
Dependencies (3)
|
|
13.6.0
minor
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.6.0
minor
Dependencies (3)
|
|
10.8.8
patch
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
10.8.8
patch
Dependencies (6)
|
|
13.5.3
patch
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.5.3
patch
Dependencies (3)
|
|
13.6.0-rc2
pre
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.6.0-rc2
pre
Dependencies (3)
|
|
13.6.0-rc
pre
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.6.0-rc
pre
Dependencies (3)
|
|
13.5.2
patch
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.5.2
patch
Dependencies (3)
|
|
10.8.7
patch
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
10.8.7
patch
Dependencies (6)
|
|
13.5.1
patch
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.5.1
patch
Dependencies (3)
|
|
13.5.0
minor
1 CVE
CVE-2025-27602
GHSA-wx5h-wqfq-v698
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactVia manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. PatchesWill be patched in 10.8.9 and 13.7.1 WorkaroundsNone available. Affected versions
10.0.0
10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.1
10.1.0
10.1.0-rc
10.1.0-rc2
10.1.1
10.2.0
+ 137 more Show less
10.2.0-rc
10.2.1
10.3.0
10.3.0-rc
10.3.1
10.3.2
10.4.0
10.4.0-rc
10.4.1
10.4.2
10.5.0
10.5.0-rc
10.5.1
10.6.0
10.6.0-rc
10.6.1
10.7.0
10.7.0-rc
10.8.0
10.8.0-rc
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
10.8.7
10.8.8
9.0.0
9.0.0-rc001
9.0.0-rc002
9.0.0-rc003
9.0.0-rc004
9.0.1
9.1.0
9.1.0-rc
9.1.1
9.1.2
9.2.0
9.2.0-rc
9.3.0
9.3.0-rc
9.3.1
9.4.0
9.4.0-rc
9.4.1
9.4.2
9.4.3
9.5.0
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.1
9.5.2
9.5.3
9.5.4
11.0.0
11.0.0-rc1
11.0.0-rc2
11.0.0-rc3
11.0.0-rc4
11.0.0-rc5
11.0.0-rc6
11.1.0
11.1.0-rc
11.2.0
11.2.0-rc
11.2.1
11.2.2
11.3.0
11.3.0-rc
11.3.1
11.4.0
11.4.0-rc
11.4.1
11.4.2
11.5.0
11.5.0-rc
12.0.0
12.0.0-rc1
12.0.0-rc2
12.0.0-rc3
12.0.0-rc4
12.0.0-rc5
12.0.1
12.1.0
12.1.0-rc
12.1.1
12.1.2
12.2.0
12.2.0-rc
12.3.0
12.3.0-rc
12.3.1
12.3.10
12.3.2
12.3.3
12.3.4
12.3.5
12.3.6
12.3.7
12.3.8
12.3.9
13.0.0
13.0.0-rc1
13.0.0-rc2
13.0.0-rc3
13.0.0-rc4
13.0.0-rc5
13.0.1
13.0.2
13.0.3
13.1.0
13.1.0-rc
13.1.1
13.2.0
13.2.0-rc
13.2.1
13.2.2
13.3.0
13.3.0-rc
13.3.1
13.3.2
13.4.0
13.4.0-rc
13.4.0-rc2
13.4.1
13.5.0
13.5.0-rc
13.5.1
13.5.2
13.5.3
13.6.0
13.6.0-rc
13.6.0-rc2
13.7.0
13.7.0-rc
Fixed in
10.8.9
13.7.1
References
Updated Mar 12, 2025 · Source: OSV.dev |
13.5.0
minor
Dependencies (3)
|