FAIL › dossier
umbraco cms
PRODUCTDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 1
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-12-22 | CVE-2025-67288 | critical | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system ad |