CVE-2013-4793: Umbraco CMS

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.

Affected products

  • Umbraco Umbraco CMS: up to and including 6.0.3

Published 2014-12-27. Last modified 2026-06-16.