FAIL › dossier
umbraco
VENDOR· dossier confidence 50%
Umbraco, a .NET-based CMS, has experienced critical security vulnerabilities, including remote code execution flaws.
PROFILE
CategoryContent Management System (CMS)What they doUmbraco is an open-source content management platform (CMS) built on the .NET framework.
SECURITY POSTURE
The company has faced notable security vulnerabilities, including critical remote code execution (RCE) flaws.
Notable failures
- CVE-2025-67288 (2025-12-22): Arbitrary file upload vulnerability in Umbraco CMS v16.3.3
- CVE-2021-33224 (2023-02-24): File upload vulnerability in Umbraco Forms v.8.7.0
Patterns: Repeated unpatched vulnerabilities
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-12-22 | CVE-2025-67288 | critical | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system ad |
| 2023-02-24 | CVE-2021-33224 | critical | File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file. |
Open questions: How has Umbraco addressed the recurring security issues?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:41:59.559197+00:00