UmbracoCms.Core
Contains the core assemblies needed to run Umbraco Cms. This package only contains assemblies and can be used for package development. Use the UmbracoCms package to setup Umbraco in Visual Studio as an ASP.NET project.
Activity
- Latest release
- 1y ago
- Total releases
- 318
- Cadence
- ~12 days
- Last 12 months
- 0
Details
- First release
- Jul 06, 2012
| Version | Released | |
|---|---|---|
8.18.15
patch
|
8.18.15
patch
Dependencies (21)
+ 13 more |
|
8.18.14
patch
|
8.18.14
patch
Dependencies (21)
+ 13 more |
|
8.18.13
patch
1 CVE
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.13
patch
Dependencies (21)
+ 13 more |
|
8.18.12
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.12
patch
Dependencies (21)
+ 13 more |
|
8.18.11
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.11
patch
Dependencies (21)
+ 13 more |
|
8.18.10
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.10
patch
Dependencies (21)
+ 13 more |
|
7.15.11
patch
3 CVEs
CVE-2020-5809
GHSA-95qr-67rx-9pgh
May 24, 2022
Umbraco CMS vulnerable to stored XSS
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 252 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-9471
GHSA-h68c-4jh3-cp9j
May 24, 2022
Umbraco CMS Authenticated File Upload
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 226 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-7210
GHSA-gqqf-8cx6-9r7h
May 24, 2022
Umbraco CMS vulnerable to CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 222 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
Fixed in
8.5.0
References
Updated Feb 22, 2024 · Source: OSV.dev |
7.15.11
patch
Dependencies (24)
+ 16 more |
|
8.18.9
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.9
patch
Dependencies (21)
+ 13 more |
|
8.18.8
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.8
patch
Dependencies (21)
+ 13 more |
|
8.18.7
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.7
patch
Dependencies (21)
+ 13 more |
|
8.18.6
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.6
patch
Dependencies (21)
+ 13 more |
|
7.15.10
patch
3 CVEs
CVE-2020-5809
GHSA-95qr-67rx-9pgh
May 24, 2022
Umbraco CMS vulnerable to stored XSS
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 252 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-9471
GHSA-h68c-4jh3-cp9j
May 24, 2022
Umbraco CMS Authenticated File Upload
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 226 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-7210
GHSA-gqqf-8cx6-9r7h
May 24, 2022
Umbraco CMS vulnerable to CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 222 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
Fixed in
8.5.0
References
Updated Feb 22, 2024 · Source: OSV.dev |
7.15.10
patch
Dependencies (24)
+ 16 more |
|
7.15.9
patch
3 CVEs
CVE-2020-5809
GHSA-95qr-67rx-9pgh
May 24, 2022
Umbraco CMS vulnerable to stored XSS
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 252 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-9471
GHSA-h68c-4jh3-cp9j
May 24, 2022
Umbraco CMS Authenticated File Upload
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 226 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-7210
GHSA-gqqf-8cx6-9r7h
May 24, 2022
Umbraco CMS vulnerable to CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 222 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
Fixed in
8.5.0
References
Updated Feb 22, 2024 · Source: OSV.dev |
7.15.9
patch
Dependencies (24)
+ 16 more |
|
7.15.8
patch
3 CVEs
CVE-2020-5809
GHSA-95qr-67rx-9pgh
May 24, 2022
Umbraco CMS vulnerable to stored XSS
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 252 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-9471
GHSA-h68c-4jh3-cp9j
May 24, 2022
Umbraco CMS Authenticated File Upload
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 226 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-7210
GHSA-gqqf-8cx6-9r7h
May 24, 2022
Umbraco CMS vulnerable to CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 222 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
Fixed in
8.5.0
References
Updated Feb 22, 2024 · Source: OSV.dev |
7.15.8
patch
Dependencies (24)
+ 16 more |
|
8.18.5
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34071
GHSA-j74q-mv2c-rxmp
May 21, 2024
Umbraco CMS Open Redirect Bypass Protection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUmbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed. Affected Version>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0 Patches8.18.14, 10.8.6, 12.3.10, 13.3.1 Affected versions
8.18.10
8.18.11
8.18.12
8.18.13
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
Fixed in
8.18.14
10.8.6
12.3.10
13.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.5
patch
Dependencies (21)
+ 13 more |
|
8.18.4
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.4
patch
Dependencies (21)
+ 13 more |
|
8.18.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.3
patch
Dependencies (21)
+ 13 more |
|
8.18.2
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.2
patch
Dependencies (21)
+ 13 more |
|
8.18.1
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.1
patch
Dependencies (21)
+ 13 more |
|
8.18.0
minor
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.0
minor
Dependencies (21)
+ 13 more |
|
8.18.0-rc2
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.0-rc2
pre
Dependencies (21)
+ 13 more |
|
8.18.0-rc
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.18.0-rc
pre
Dependencies (21)
+ 13 more |
|
8.17.2
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.17.2
patch
Dependencies (21)
+ 13 more |
|
8.17.1
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.17.1
patch
Dependencies (21)
+ 13 more |
|
8.17.0
minor
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.17.0
minor
Dependencies (21)
+ 13 more |
|
8.17.0-rc2
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.17.0-rc2
pre
Dependencies (21)
+ 13 more |
|
8.17.0-rc
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.17.0-rc
pre
Dependencies (21)
+ 13 more |
|
8.15.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.15.3
patch
Dependencies (21)
+ 13 more |
|
8.14.4
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.14.4
patch
Dependencies (21)
+ 13 more |
|
8.16.0
minor
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.16.0
minor
Dependencies (21)
+ 13 more |
|
8.15.2
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.15.2
patch
Dependencies (21)
+ 13 more |
|
8.14.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.14.3
patch
Dependencies (21)
+ 13 more |
|
8.16.0-rc
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.16.0-rc
pre
Dependencies (21)
+ 13 more |
|
8.14.2
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.14.2
patch
Dependencies (21)
+ 13 more |
|
8.15.1
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.15.1
patch
Dependencies (21)
+ 13 more |
|
8.15.0
minor
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.15.0
minor
Dependencies (21)
+ 13 more |
|
8.15.0-rc
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.15.0-rc
pre
Dependencies (21)
+ 13 more |
|
8.14.1
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.14.1
patch
Dependencies (21)
+ 13 more |
|
8.14.0
minor
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.14.0
minor
Dependencies (21)
+ 13 more |
|
8.11.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.11.3
patch
Dependencies (21)
+ 13 more |
|
8.12.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.12.3
patch
Dependencies (21)
+ 13 more |
|
8.13.1
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.13.1
patch
Dependencies (21)
+ 13 more |
|
8.14.0-rc
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.14.0-rc
pre
Dependencies (21)
+ 13 more |
|
8.13.0
minor
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.13.0
minor
Dependencies (21)
+ 13 more |
|
8.13.0-rc
pre
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.13.0-rc
pre
Dependencies (21)
+ 13 more |
|
8.12.2
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.12.2
patch
Dependencies (21)
+ 13 more |
|
8.9.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.9.3
patch
Dependencies (21)
+ 13 more |
|
8.10.3
patch
1 CVE
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.10.3
patch
Dependencies (21)
+ 13 more |
|
8.6.8
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5809
GHSA-95qr-67rx-9pgh
May 24, 2022
Umbraco CMS vulnerable to stored XSS
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 252 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
References Updated Feb 16, 2024 · Source: OSV.dev |
8.6.8
patch
Dependencies (21)
+ 13 more |
|
8.7.3
patch
2 CVEs
CVE-2024-35218
GHSA-gvpc-3pj6-4m9w
May 21, 2024
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactStored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. Affected versionsUmbraco CMS >= 8.00 PatchesThis is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
+ 93 more Show less
8.10.0-rc
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc
8.11.1
8.11.2
8.11.3
8.12.0
8.12.0-rc
8.12.1
8.12.2
8.12.3
8.13.0
8.13.0-rc
8.13.1
8.14.0
8.14.0-rc
8.14.1
8.14.2
8.14.3
8.14.4
8.15.0
8.15.0-rc
8.15.1
8.15.2
8.15.3
8.16.0
8.16.0-rc
8.17.0
8.17.0-rc
8.17.0-rc2
8.17.1
8.17.2
8.18.0
8.18.0-rc
8.18.0-rc2
8.18.1
8.18.10
8.18.11
8.18.12
8.18.2
8.18.3
8.18.4
8.18.5
8.18.6
8.18.7
8.18.8
8.18.9
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
8.9.2
8.9.3
Fixed in
8.18.13
10.8.4
12.3.7
13.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5809
GHSA-95qr-67rx-9pgh
May 24, 2022
Umbraco CMS vulnerable to stored XSS
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. Affected versions
4.10.0
4.10.0-beta
4.10.0-rc
4.10.1
4.11.0
4.11.1
4.11.10
4.11.2
4.11.2.1
4.11.2.2
4.11.2.3
4.11.3
+ 252 more Show less
4.11.3.1
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.7.2
4.8.0
4.8.0-beta
4.8.1
4.9.0
4.9.1
6.0.0
6.0.0-RC
6.0.0-beta
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.7.1
6.1.0
6.1.0-beta
6.1.0-beta-2
6.1.1
6.1.2
6.1.2.1
6.1.2.2
6.1.3
6.1.4
6.1.5
6.1.6
6.2.0
6.2.0-RC
6.2.0.1-RC
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
7.0.0
7.0.0-RC
7.0.0-alpha
7.0.0-beta
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
7.1.0-RC
7.1.1
7.1.10
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.10.0
7.10.1
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.11.0
7.11.1
7.11.2
7.11.3
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.13.0
7.13.1
7.13.2
7.13.3
7.14.0
7.14.1
7.15.0
7.15.1
7.15.10
7.15.11
7.15.2
7.15.3
7.15.4
7.15.5
7.15.6
7.15.7
7.15.8
7.15.9
7.2.0
7.2.0-RC
7.2.0-beta
7.2.0-beta2
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.5-RC
7.2.6
7.2.7
7.2.8
7.2.9
7.3.0
7.3.0-RC
7.3.0-beta
7.3.0-beta2
7.3.0-beta3
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0
7.4.0-RC1
7.4.0-beta
7.4.0-beta2
7.4.1
7.4.2
7.4.3
7.4.4
7.5.0
7.5.0-beta
7.5.0-beta2
7.5.1
7.5.10
7.5.11
7.5.12
7.5.13
7.5.14
7.5.15
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.6.0
7.6.0-RC
7.6.0-beta
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
7.7.0
7.7.0-beta
7.7.1
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.8.0
7.8.0-beta
7.8.1
7.8.2
7.8.3
7.8.4
7.9.0
7.9.1
7.9.2
7.9.3
7.9.4
7.9.5
7.9.6
7.9.7
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.0-rc
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.4.0
8.4.0-rc
8.4.1
8.4.2
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.6.0
8.6.0-rc
8.6.1
8.6.2
8.6.3
8.6.4
8.6.5
8.6.6
8.6.7
8.6.8
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.8.0
8.8.0-rc
8.8.1
8.8.2
8.8.3
8.8.4
8.9.0
8.9.0-rc
8.9.1
References Updated Feb 16, 2024 · Source: OSV.dev |
8.7.3
patch
Dependencies (21)
+ 13 more |