CVE-2015-8814: Umbraco

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.

Affected products

  • Umbraco Umbraco: version 7.3.8 only

Published 2017-03-03. Last modified 2026-06-17.