CVE-2024-35218: Umbraco CMS

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. This vulnerability has been patched in version(s) 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer.

Affected products

  • Umbraco Umbraco CMS: from 8.0.0, before 8.18.13 (fixed in 8.18.13); from 10.0.0, before 10.8.4 (fixed in 10.8.4); from 12.0.0, before 12.3.7 (fixed in 12.3.7); from 13.0.0, before 13.1.1 (fixed in 13.1.1)

Published 2024-05-21. Last modified 2026-06-17.