CVE-2019-25137: Umbraco CMS

High severity, CVSS 7.2. EPSS: 4.1% chance of exploitation in the next 30 days.

Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.

Affected products

  • Umbraco Umbraco CMS: from 4.11.8, up to and including 7.15.10

Published 2023-05-18. Last modified 2026-06-17.