CVE-2025-32017: Umbraco CMS

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.

Affected products

  • Umbraco Umbraco CMS: from 14.0.0, before 14.3.4 (fixed in 14.3.4); from 15.0.0, before 15.3.1 (fixed in 15.3.1)

Published 2025-04-08. Last modified 2026-06-17.