CVE-2012-10054: Umbraco CMS

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

Affected products

  • Umbraco Umbraco CMS: before 4.7.1 (fixed in 4.7.1)

Published 2025-08-13. Last modified 2026-06-16.