CVE-2023-38694: Umbraco CMS

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue.

Affected products

  • Umbraco Umbraco CMS: from 8.0.0, before 8.18.10 (fixed in 8.18.10); from 9.0.0, before 10.7.0 (fixed in 10.7.0); from 11.0.0, before 12.1.0 (fixed in 12.1.0)

Published 2023-12-12. Last modified 2026-06-17.