CVE-2025-24012
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 79
Summary
CVE-2025-24012 is a cross-site scripting (XSS) vulnerability affecting versions 14.0.0 and prior to 14.3.2 and 15.1.2 of Umbraco, a free and open-source .NET content management system. Authenticated users can exploit this issue by injecting malicious scripts into certain localized backoffice components, posing a security risk. Versions 14.3.2 and 15.1.2 have been released with necessary patches to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CMs
Affected Vendors
- Pluck -