UmbracoForms
Umbraco Forms is an extension for Umbraco CMS allowing editors to create and manage forms and review submissions. The packages available from this feed can be used with Umbraco CMS versions up to version 8. For Umbraco CMS version 9, please use the feed available at https://www.nuget.org/packages/Umbraco.Forms/
Activity
- Latest release
- 1y ago
- Total releases
- 132
- Cadence
- ~14 days
- Last 12 months
- 0
Details
- First release
- Oct 13, 2016
| Version | Released | |
|---|---|---|
8.13.16
patch
2 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev |
8.13.16
patch
Dependencies (2)
|
|
8.13.15
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.15
patch
Dependencies (2)
|
|
8.13.14
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.14
patch
Dependencies (2)
|
|
8.13.13
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.13
patch
Dependencies (2)
|
|
8.13.12
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.12
patch
Dependencies (2)
|
|
8.13.11
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.11
patch
Dependencies (2)
|
|
8.13.10
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.10
patch
Dependencies (2)
|
|
8.13.9
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.9
patch
Dependencies (2)
|
|
8.13.8
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.8
patch
Dependencies (2)
|
|
8.13.7
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.7
patch
Dependencies (2)
|
|
8.13.6
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.6
patch
Dependencies (2)
|
|
8.13.5
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.5
patch
Dependencies (2)
|
|
8.13.4
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.4
patch
Dependencies (2)
|
|
7.5.10
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.10
patch
Dependencies (2)
|
|
8.13.3
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.3
patch
Dependencies (2)
|
|
8.13.2
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.2
patch
Dependencies (2)
|
|
8.13.1
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.1
patch
Dependencies (2)
|
|
8.13.0
minor
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.0
minor
Dependencies (2)
|
|
8.13.0-rc001
pre
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.13.0-rc001
pre
Dependencies (2)
|
|
8.12.2
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.12.2
patch
Dependencies (2)
|
|
8.12.1
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.12.1
patch
Dependencies (2)
|
|
8.12.0
minor
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.12.0
minor
Dependencies (2)
|
|
7.5.9
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.9
patch
Dependencies (2)
|
|
8.12.0-rc001
pre
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.12.0-rc001
pre
Dependencies (2)
|
|
7.5.8
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.8
patch
Dependencies (2)
|
|
8.11.0
minor
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.11.0
minor
Dependencies (2)
|
|
8.10.3
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.10.3
patch
Dependencies (2)
|
|
8.11.0-rc001
pre
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.11.0-rc001
pre
Dependencies (2)
|
|
7.5.7
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.7
patch
Dependencies (2)
|
|
8.10.2
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.10.2
patch
Dependencies (2)
|
|
8.10.1
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.10.1
patch
Dependencies (2)
|
|
7.5.6
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.6
patch
Dependencies (2)
|
|
8.10.0
minor
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.10.0
minor
Dependencies (2)
|
|
8.10.0-rc001
pre
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.10.0-rc001
pre
Dependencies (2)
|
|
8.9.1
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.9.1
patch
Dependencies (2)
|
|
8.9.0
minor
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.9.0
minor
Dependencies (2)
|
|
7.5.5
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.5
patch
Dependencies (2)
|
|
8.9.0-rc001
pre
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.9.0-rc001
pre
Dependencies (2)
|
|
8.8.0
minor
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.8.0
minor
Dependencies (2)
|
|
8.8.0-rc001
pre
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev |
8.8.0-rc001
pre
Dependencies (2)
|
|
6.0.10
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
6.0.10
patch
Dependencies (2)
|
|
4.4.9
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
4.4.9
patch
Dependencies (2)
|
|
7.1.4
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.1.4
patch
Dependencies (2)
|
|
4.4.8
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
4.4.8
patch
Dependencies (2)
|
|
7.2.1
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.2.1
patch
Dependencies (2)
|
|
7.3.2
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.3.2
patch
Dependencies (2)
|
|
6.0.9
patch
3 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
6.0.9
patch
Dependencies (2)
|
|
7.4.3
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.4.3
patch
Dependencies (2)
|
|
7.5.4
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
7.5.4
patch
Dependencies (2)
|
|
8.0.2
patch
4 CVEs
CVE-2025-68924
GHSA-vrgw-pc9c-qrrc
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWithin Umbraco Forms, configuring a malicious URL on the Webservice data source can result in Remote Code Execution. This affects all Umbraco Forms versions running on .NET Framework (up to and including version 8). PatchesThe affected Umbraco Forms versions are all End-of-Life (EOL) and not supported anymore, hence no patches will be released. Upgrading to any of the currently supported versions (v13, v16 or v17) is recommended. WorkaroundsIf none of the configured Forms data sources uses the Webservice type, it can be safely excluded by adding the following code to the application. This will completely remove the option to select/use this data source within the Backoffice and thereby mitigate the vulnerability.
Any Webservice data source that is configured and still in use should be replaced with a custom implementation instead, before applying the above code. If this is not feasible, the vulnerability can be minimized by revoking the 'Manage Data Sources' from any non-administrator user and/or inheriting from the default ReferencesWhen upgrading to a supported version, please take the Forms version specific upgrade notes into account and check the CMS upgrade documentation. Content and schema can also be migrated straight to the latest version using Deploy export/import with migrations. Implementation details on data sources are not extensively documented, but they follow the general Forms provider model and inherit from A special thanks to Piotr Bazydlo (@chudyPB) of watchTowr for finding and disclosing this vulnerability Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 138 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-47280
GHSA-2qrj-g9hq-chph
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
Network
Low
None
ImpactThe 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems). PatchesThis issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. WorkaroundsUnpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
+ 98 more Show less
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.16
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
References Updated May 13, 2025 · Source: OSV.dev
CVE-2025-23041
GHSA-9v8m-qv22-f268
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
5.8
/ 10
Medium
Network
Low
None
None
Changed
None
None
Low
ImpactCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side. PatchesPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2 Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 137 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.10.0
8.10.0-rc001
8.10.1
8.10.2
8.10.3
8.11.0
8.11.0-rc001
8.12.0
8.12.0-rc001
8.12.1
8.12.2
8.13.0
8.13.0-rc001
8.13.1
8.13.10
8.13.11
8.13.12
8.13.13
8.13.14
8.13.15
8.13.2
8.13.3
8.13.4
8.13.5
8.13.6
8.13.7
8.13.8
8.13.9
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.6.0
8.6.1
8.6.2
8.7.0
8.7.0-rc
8.7.1
8.7.2
8.7.3
8.7.4
8.7.5
8.7.6
8.8.0
8.8.0-rc001
8.9.0
8.9.0-rc001
8.9.1
Fixed in
8.13.16
References Updated Sep 19, 2025 · Source: OSV.dev
CVE-2020-7685
GHSA-8m73-w2r2-6xxj
Jul 29, 2020
Insecure defaults in UmbracoForms
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies. Affected versions
4.0.0
4.0.1
4.0.1-Build111
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
+ 82 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.1
4.3.2
4.3.3
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
6.0.0
6.0.1
6.0.10
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.5.10
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
8.0.0
8.0.1
8.0.2
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.4.0
8.4.1
References Updated Nov 08, 2023 · Source: OSV.dev |
8.0.2
patch
Dependencies (2)
|