Umbraco.Cms.Api.Management
NuGet2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Umbraco.Cms.Api.Managementpage 1 of 1
- CVE-2024-43376MEDIUMCVSS 4.3EG 4.3✓ Fixed in 14.1.22024-08-20
vulnerable: 14.0.0, 14.1.0, 14.1.0-rc, 14.1.0-rc2, 14.1.1
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
- CVE-2025-27601MEDIUMCVSS 4.3EG 4.3✓ Fixed in 15.2.32025-03-11
vulnerable: 15.0.0 ... 15.2.2 (14 versions)
Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to…
Check whether Umbraco.Cms.Api.Management is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Umbraco.Cms.Api.Management CVEs against the assets you own.
Start Free Scan →