CVE-2025-23041: Umbraco Forms
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
Affected products
- Umbraco Umbraco Forms: before 8.13.15 (fixed in 8.13.15); from 10.0.0, before 10.5.7 (fixed in 10.5.7); from 13.0.0, before 13.2.2 (fixed in 13.2.2); from 14.0.0, before 14.1.2 (fixed in 14.1.2)
Published 2025-01-14. Last modified 2026-06-17.