Where
AND
-Infinity
0
Severity
5.3
EPSS
0.05%
Infoleak
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Impact

Based on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.

Patches

Patched in 14.3.2 and 15.1.2.

Workarounds

None available.

1 / 2
Source: GitHub
First published (updated )
Severity
5.4
EPSS
0.04%
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Impact Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.

Patches Will be patched in 14.3.2 and 15.1.2.

Note: This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil

1 / 2
Source: GitHub
First published (updated )
Severity
6.5
EPSS
0.07%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N

Impact An improper access control issue has been identified, allowing low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section

1 / 2
Source: GitHub
First published (updated )
Severity
8.7
XSS
AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Impact This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.

Patches Will be patched in 14.3.1 and 15.0.0.

Workarounds Ensure that access to the Dictionary section is only granted to trusted users.

1 / 2
Source: GitHub
First published (updated )
Severity
5.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.

Explanation of the vulnerability Management API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.

E.g. when paging with negative numbers in some apis

1 / 2
Source: GitHub
First published (updated )
Severity
5.4
AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Impact As an authenticated user one can access a few unintended endpoints

Explanation of the vulnerability Few endpoints in Umbraco Management API was not protected by a specific section. These just required you to be authenticated. Due to the fact that a member is also just authenticated, it was possible to get info from these endpoints using a member token.

1 / 2
Source: GitHub
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203