Skip to content
COOEY

EXPOSURES › CVE-2025-67288

CVE-2025-67288

CRITICAL
DETAIL
SourceNVD · cve Published2025-12-22 CVSS10.0 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-67288 ↗
⚡ RCE ◐ ZERO-DAY SHAME 50/100 rcezero-day

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system ad

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.