CVE-2012-10054: Umbraco CMS
Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.
Affected products
- Umbraco Umbraco CMS: before 4.7.1 (fixed in 4.7.1)
Published 2025-08-13. Last modified 2026-06-16.