CVE-2015-8813: Umbraco

High severity, CVSS 8.2. EPSS: 11.2% chance of exploitation in the next 30 days.

The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.

Affected products

  • Umbraco Umbraco: up to and including 7.3.8

Published 2017-03-03. Last modified 2026-06-17.