Skip to content
COOEY

FAIL › dossier

umbraco

VENDOR

· dossier confidence 50%

Umbraco, a .NET-based CMS, has experienced critical security vulnerabilities, including remote code execution flaws.

PROFILE
CategoryContent Management System (CMS)What they doUmbraco is an open-source content management platform (CMS) built on the .NET framework.
SECURITY POSTURE

The company has faced notable security vulnerabilities, including critical remote code execution (RCE) flaws.

Notable failures
  • CVE-2025-67288 (2025-12-22): Arbitrary file upload vulnerability in Umbraco CMS v16.3.3
  • CVE-2021-33224 (2023-02-24): File upload vulnerability in Umbraco Forms v.8.7.0
Patterns: Repeated unpatched vulnerabilities
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-12-22 CVE-2025-67288 critical An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system ad
2023-02-24 CVE-2021-33224 critical File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
Open questions: How has Umbraco addressed the recurring security issues?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:41:59.559197+00:00