CVE-2025-24012: Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability
Impact Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.
Patches Will be patched in 14.3.2 and 15.1.2.
Note: This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil
Other sources
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24012?
CVE-2025-24012 is classified as a medium severity XSS vulnerability affecting localized backoffice components.
How do I fix CVE-2025-24012?
To fix CVE-2025-24012, upgrade to versions 14.3.2 or 15.1.2 of the affected Umbraco packages.
What software is affected by CVE-2025-24012?
CVE-2025-24012 affects the @umbraco-cms/backoffice and Umbraco.Cms.StaticAssets packages in specific version ranges.
Who reported CVE-2025-24012?
CVE-2025-24012 was reported by Pratik Patil from NetSPI.
When will the patches for CVE-2025-24012 be available?
Patches for CVE-2025-24012 will be available in the upcoming releases of version 14.3.2 and 15.1.2.