Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10387 | Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users |
Github GHSA |
GHSA-q62r-8ppj-xvf4 | Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users |
Mon, 22 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* |
Wed, 09 Apr 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 08 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1. | |
| Title | Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-09T17:13:15.314Z
Reserved: 2025-04-01T21:57:32.953Z
Link: CVE-2025-32017
Updated: 2025-04-08T16:01:31.656Z
Status : Analyzed
Published: 2025-04-08T16:15:27.320
Modified: 2025-09-22T13:56:32.683
Link: CVE-2025-32017
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:48Z
EUVD
Github GHSA