CVE-2024-35218: Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane

Published May 21, 2024
·
Updated

Impact Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application.

Affected versions Umbraco CMS >= 8.00

Patches This is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer

Other sources

Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. This vulnerability has been patched in version(s) 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer.

MITRE

Affected Software

8 affected componentsFixes available
nuget/UmbracoCms.Core>=13.0.0<13.1.1
13.1.1
nuget/UmbracoCms.Core>=12.0.0<12.3.7
12.3.7
nuget/UmbracoCms.Core>=10.0.0<10.8.4
10.8.4
nuget/UmbracoCms.Core>=8.0.0<8.18.13
8.18.13
Umbraco Umbraco CMS>=8.0.0<8.18.13
Umbraco Umbraco CMS>=10.0.0<10.8.4
Umbraco Umbraco CMS>=12.0.0<12.3.7
Umbraco Umbraco CMS>=13.0.0<13.1.1

Event History

May 21, 2024
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·02:47 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-35218?

CVE-2024-35218 has a medium severity rating due to its potential for stored cross-site scripting (XSS) attacks.

2

How do I fix CVE-2024-35218?

To fix CVE-2024-35218, update Umbraco CMS to version 8.18.13, 10.8.4, 12.3.7, or 13.1.1.

3

Which versions of Umbraco CMS are affected by CVE-2024-35218?

CVE-2024-35218 affects all versions of Umbraco CMS greater than or equal to 8.00.

4

What type of vulnerability is identified in CVE-2024-35218?

CVE-2024-35218 is a stored cross-site scripting (XSS) vulnerability.

5

What impact does CVE-2024-35218 have on users?

The impact of CVE-2024-35218 allows attackers with access to the back office to bring in malicious content, compromising the website or application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203