CVE-2012-1301: Umbraco CMS

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

Affected products

  • Umbraco Umbraco CMS: version 4.7.0 only

Published 2017-04-13. Last modified 2026-06-16.