Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vrgw-pc9c-qrrc | UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation |
Fri, 20 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Umbraco umbraco Forms
|
|
| CPEs | cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Umbraco umbraco Forms
|
Fri, 16 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution. | |
| First Time appeared |
Umbraco
Umbraco forms |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:2.3:a:umbraco:forms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Umbraco
Umbraco forms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-16T19:00:26.430Z
Reserved: 2025-12-24T00:00:00.000Z
Link: CVE-2025-68924
Updated: 2026-01-16T19:00:19.293Z
Status : Analyzed
Published: 2026-01-16T19:16:18.370
Modified: 2026-02-20T19:51:46.613
Link: CVE-2025-68924
No data.
OpenCVE Enrichment
No data.
Github GHSA