Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

nuget Umbraco.CMS Security Advisories

Loading...
Low
GSA_kwCzR0hTQS02eG14LTg1eDMtNGN2Ms4AA3ug
Stored XSS via SVG File Upload
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS03eDc0LWg4Y3ctcWh4cc4AA3uf
Brute force exploit can be used to collect valid usernames
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS04cXA4LTlycHctajQ2Y84AA3ue
SMTP misconfiguration leading to "Forgot Password" exploit that leaks registered user email.
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS1jZnI1LTdwNTQtNHFnOM4AA3ud
Privilege Escalation using Spoofing
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS02MzI0LTUycHItaDRwNc4AA3uc
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS12OThtLTM5OHgtMjY5cs4AA3ub
DOM-XSS on Backoffice login screen.
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS0zMzV4LTV3Y20tOGp2Ms4AA3ua
Backoffice User can bypass "Publish" restriction
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS14eGM2LTM1cjctNzk2d84AA3uY
Possible injection of HTML into user invite mails
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: 3 months ago
High
GSA_kwCzR0hTQS14MzRqLXd4cTgtN3Zjbc4AAb4d
Umbraco CMS vulnerable to CSRF
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: almost 2 years ago
High
GSA_kwCzR0hTQS01ZjZwLTRoeHEtcmp4bc4AAb4c
Umbraco CMS vulnerable to CSRF
Ecosystems: nuget
Packages: Umbraco.CMS
Source: GitHub Advisory Database
Published: almost 2 years ago
Filter by Package
Microsoft.ChakraCore 247 DotNetNuke.Core 19 Microsoft.AspNetCore.App.Runtime.win-x86 18 Microsoft.AspNetCore.App.Runtime.win-x64 18 Microsoft.AspNetCore.App.Runtime.win-arm 17 Microsoft.AspNetCore.App.Runtime.linux-arm 17 Microsoft.AspNetCore.App.Runtime.osx-x64 16 Microsoft.AspNetCore.App.Runtime.linux-x64 16 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 16 Microsoft.AspNetCore.App.Runtime.linux-arm64 16 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 15 Microsoft.AspNetCore.App.Runtime.win-arm64 15 Microsoft.NETCore.App.Runtime.win-x86 11 Microsoft.NETCore.App.Runtime.win-x64 11 Microsoft.NETCore.App.Runtime.win-arm64 11 Microsoft.AspNetCore.App.Runtime.linux-musl-arm 11 Umbraco.CMS 10 jquery 10 org.webjars.npm:jquery 10 jquery-rails 10 Microsoft.AspNetCore.All 10 Microsoft.NETCore.App 10 Microsoft.NetCore.App.Runtime.win-x86 9 Microsoft.NetCore.App.Runtime.win-x64 9 Microsoft.NetCore.App.Runtime.win-arm64 9 Microsoft.NetCore.App.Runtime.win-arm 9 Microsoft.AspNetCore.App.Runtime.osx-arm64 8 Microsoft.AspNetCore.App 8 Microsoft.NETCore.App.Runtime.linux-x64 8 jQuery 8 Microsoft.NETCore.App.Runtime.linux-musl-x64 8 Microsoft.NETCore.App.Runtime.linux-musl-arm64 8 Microsoft.NETCore.App.Runtime.linux-arm64 8 Microsoft.NETCore.App.Runtime.linux-arm 8 jquery-ui-rails 8 jquery-ui 8 org.webjars.npm:jquery-ui 8 jQuery.UI.Combined 8 tinymce/tinymce 7 tinymce 7 Microsoft.NETCore.App.Runtime.osx-x64 7 TinyMCE 7 Microsoft.NETCore.App.Runtime.win-arm 7 CefSharp.Common 7 OPCFoundation.NetStandard.Opc.Ua.Core 7 Microsoft.AspNetCore.Mvc.Core 6 Microsoft.NETCore.App.Runtime.linux-musl-arm 6 NuGet.CommandLine 5 Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 5 Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 5 Microsoft.NETCore.App.Runtime.Mono.osx-x64 5 Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 5 Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 5 Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 5 Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 5 Microsoft.NETCore.App.Runtime.rhel.6-x64 5 Microsoft.NETCore.App.Runtime.Mono.linux-arm 5 Microsoft.WindowsDesktop.App.Runtime.win-x64 5 Microsoft.NETCore.App.Runtime.Mono.linux-x64 5 CefSharp.Wpf.HwndHost 5 CefSharp.WinForms 5 CefSharp.Wpf 5 Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 5 Microsoft.NETCore.App.Runtime.Mono.linux-arm64 5 Microsoft.AspNetCore.Mvc.Cors 5 System.Text.Encodings.Web 5 System.Net.Http 5 Microsoft.AspNetCore.Server.Kestrel.Core 5 System.Net.Security 4 System.Net.WebSockets.Client 4 Microsoft.AspNetCore.Mvc.Abstractions 4 Microsoft.AspNetCore.Mvc.ApiExplorer 4 SharpZipLib 4 System.Security.Cryptography.Xml 4 Microsoft.AspNetCore.Mvc.Formatters.Json 4 Microsoft.NetCore.App.Runtime.linux-x64 4 Microsoft.NetCore.App.Runtime.linux-arm 4 Microsoft.NetCore.App.Runtime.linux-arm64 4 Microsoft.NetCore.App.Runtime.linux-musl-arm 4 Microsoft.WindowsDesktop.App.Runtime.win-x86 4 Microsoft.AspNetCore.Mvc.DataAnnotations 4 Microsoft.NetCore.App.Runtime.linux-musl-arm64 4 Microsoft.NetCore.App.Runtime.linux-musl-x64 4 Microsoft.NetCore.App.Runtime.osx-arm64 4 Microsoft.AspNetCore.Mvc.Formatters.Xml 4 Microsoft.AspNetCore.Mvc.Localization 4 Microsoft.AspNetCore.Mvc 4 Microsoft.NetCore.App.Runtime.osx-x64 4 Microsoft.AspNetCore.Mvc.Razor.Host 4 Microsoft.AspNetCore.Mvc.Razor 4 Microsoft.AspNetCore.Mvc.TagHelpers 4 Microsoft.AspNetCore.Mvc.ViewFeatures 4 Microsoft.AspNetCore.Mvc.WebApiCompatShim 4 System.Net.Http.WinHttpHandler 4 OPCFoundation.NetStandard.Opc.Ua 4 Serenity.Net.Core 4 SSCMS 4 AjaxNetProfessional 4 PeterO.Cbor 3 Sustainsys.Saml2 3 CefSharp.Common.NETCore 3 UmbracoCms 3 Microsoft.WindowsDesktop.App.Runtime.win-arm64 3 NuGet.Commands 3 OPCFoundation.NetStandard.Opc.Ua.Server 3 System.Private.Uri 3 Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.win-x64 2 Microsoft.NETCore.App.Runtime.Mono.win-x86 2 Microsoft.NETCore.App.Runtime.osx-arm64 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 2 OrchardCore 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.osx-arm64 2 Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 2 Umbraco.Cms.Core 2 DisCatSharp 2 Microsoft.Owin 2 elFinder.NetCore 2 Yarp.ReverseProxy 2 starkbank-ecdsa 2 jquery 2 Serenity.Net.Web 2 sharpcompress 2 System.Management.Automation 2 Bootstrap.Less 2 bootstrap 2 bootstrap.sass 2 Microsoft.AspNetCore.Identity 2 System.ServiceModel.Duplex 2 System.ServiceModel.Security 2 System.Private.ServiceModel 2 System.ServiceModel.NetTcp 2 System.ServiceModel.Http 2 System.ServiceModel.Primitives 2 protobuf 2 google/protobuf 2 github.com/protocolbuffers/protobuf 2 Google.Protobuf 2 Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv 2 Microsoft.AspNetCore.Server.HttpSys 2 HtmlSanitizer 2 ServiceStack 2 UmbracoCMS.Core 2 Microsoft.Data.SqlClient 2 System.Data.SqlClient 2 Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 2 Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 2 Microsoft.NETCore.App.Runtime.browser-wasm 2 Microsoft.Native.Quic.MsQuic.Schannel 2 Microsoft.Native.Quic.MsQuic.OpenSSL 2 jquery-validation 2 jQuery.Validation 2 NuGet.Protocol 2 moment 2 Moment.js 2 Snowflake.Data 2 Microsoft.IdentityModel.JsonWebTokens 2 log4net 2 System.IdentityModel.Tokens.Jwt 2 Newtonsoft.Json 2 Microsoft.AspNetCore.Http.Connections 2 TGServiceInterface 2 Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm 2 Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 2 Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 2 Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.android-x86 2 Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.browser-wasm 2 Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm64 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 2 Piranha 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm 2 Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.android-arm 2 Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 2 Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.android-x64 2 Microsoft.NETCore.App.Runtime.Mono.android-arm64 2 Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 2 Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 2 Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 2 Imageflow.NativeRuntime.ubuntu_16_04-x86_64 1 Imageflow.NativeRuntime.ubuntu-x86_64-haswell 1 Imageflow.NativeRuntime.osx_10_11-x86_64 1 Akka 1 Imageflow.NativeTool.win-x86_64 1 Imageflow.NativeTool.osx-x86_64 1 Imageflow.NativeRuntime.ubuntu_18_04-x86_64 1 Imageflow.NativeTool.win-x86 1 Microsoft.NETCore.App.Runtime.tvos-x64 1 Imageflow.NativeTool.ubuntu-x86_64 1 Microsoft.NETCore.App.Runtime.tvos-arm64 1 Microsoft.NETCore.App.Runtime.ios-x64 1 Imageflow.NativeTool.ubuntu-x86_64-haswell 1 Microsoft.NETCore.App.Runtime.ios-x86 1 Imageflow.NativeRuntime.ubuntu_18_04-x86_64-haswell 1 CoreFtp 1 DotNetNuke.Web 1 YamlDotNet 1 Wire 1 YamlDotNet.Signed 1 recurly-api-client 1 System.Linq.Dynamic.Core 1 SinGooCMS.Utility 1 C1CMS.Assemblies 1 Bond.Core.CSharp 1 System.Security.Cryptography.X509Certificates 1 Imageflow.AllPlatforms 1 Imageflow.Server 1 ImageResizer.Plugins.Imageflow 1 Imageflow.NativeRuntime.win-x86_64 1 Imageflow.NativeRuntime.osx-x86_64 1 Imageflow.NativeRuntime.win-x86 1 Imageflow.NativeRuntime.ubuntu-x86_64 1 Nancy 1 Microsoft.AspNetCore.Components 1 Microsoft.NETCore.App.Host.win-arm64 1 MongoDB.Driver 1 Microsoft.AspNetCore.SignalR.Protocols.MessagePack 1 Microsoft.AspNetCore.WebSockets 1 System.Net.WebSockets.WebSocketProtocol 1 Microsoft.NETCore.App.Host.win-arm 1 Microsoft.NETCore.App.Host.rhel.6-x64 1 Microsoft.NETCore.App.Host.osx-x64 1 Microsoft.NETCore.App.Host.linux-x64 1 Microsoft.NETCore.App.Host.linux-musl-x64 1 Microsoft.NETCore.App.Host.linux-musl-arm64 1 Microsoft.NETCore.App.Host.linux-arm64 1 Microsoft.NETCore.App.Host.linux-arm 1 Microsoft.WindowsDesktop.App.Ref 1 QuantConnect.Common 1 AgileConfig.Client 1 NuGet.Packaging 1 umbraco 1 Imageflow.NativeTool.ubuntu_18_04-x86_64-haswell 1