CVE-2024-48925: Umbraco CMS
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section. Version 14.3.0 contains a patch.
Affected products
- Umbraco Umbraco CMS: from 14.0.0, before 14.3.0 (fixed in 14.3.0)
Published 2024-10-22. Last modified 2026-06-17.