CVE-2024-28868: Umbraco CMS

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.

Affected products

  • Umbraco Umbraco CMS: from 10.0.0, before 10.8.5 (fixed in 10.8.5)

Published 2024-03-20. Last modified 2026-06-17.