CVE-2025-32017: Umbraco CMS
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.
Affected products
- Umbraco Umbraco CMS: from 14.0.0, before 14.3.4 (fixed in 14.3.4); from 15.0.0, before 15.3.1 (fixed in 15.3.1)
Published 2025-04-08. Last modified 2026-06-17.