CVE-2020-29454: Umbraco CMS

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.

Affected products

  • Umbraco Umbraco CMS: from 8.0.0, up to and including 8.9.1

Published 2020-12-02. Last modified 2026-06-17.