Vulnerabilities
Vulnerable Software
Umbraco:  >> Umbraco Cms  >> 17.3.4  Security Vulnerabilities
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.
CVSS Score
4.6
EPSS Score
0.001
Published
2026-06-10
Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. This issue has been patched in versions 13.14.0 and 17.4.0.
CVSS Score
5.4
EPSS Score
0.002
Published
2026-06-10


Contact Us

Shodan ® - All rights reserved