Umbraco.Cms.Core
NuGet3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Umbraco.Cms.Corepage 1 of 1
- CVE-2022-22690HIGHCVSS 8.6EG 8.6✓ Fixed in 9.2.02022-01-18
vulnerable: 9.0.0 ... 9.2.0-rc (11 versions)
Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and t…
- CVE-2022-22691MEDIUMCVSS 6.8EG 6.8✓ Fixed in 9.2.02022-01-18
vulnerable: 9.0.0 ... 9.2.0-rc (11 versions)
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the…
- CVE-2024-29035MEDIUMCVSS 4.1EG 4.1✓ Fixed in 13.1.12024-04-17
vulnerable: 13.0.0 ... 13.1.0-rc (6 versions)
Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.
Check whether Umbraco.Cms.Core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Umbraco.Cms.Core CVEs against the assets you own.
Start Free Scan →