Vulnerability Description
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 14.0.0, < 14.3.2 |
Related Weaknesses (CWE)
References
- https://github.com/umbraco/Umbraco-CMS/commit/d4f8754f933895b3a329296e25ddea6f84Patch
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wv8v-rmw2-25wcVendor Advisory
FAQ
What is CVE-2025-24012?
CVE-2025-24012 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vul...
How severe is CVE-2025-24012?
CVE-2025-24012 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24012?
Check the references section above for vendor advisories and patch information. Affected products include: Umbraco Umbraco Cms.