CVE-2026-46609: Umbraco CMS
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.
Affected products
- Umbraco Umbraco CMS: from 14.0.0, before 17.4.0 (fixed in 17.4.0)
Published 2026-06-10. Last modified 2026-06-17.