CVE-2013-4793: Umbraco CMS
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
Affected products
- Umbraco Umbraco CMS: up to and including 6.0.3
Published 2014-12-27. Last modified 2026-06-16.