{"id":"CVE-2025-24012","aliases":["GHSA-wv8v-rmw2-25wc"],"url":"https://o3.security/vulnerability/CVE-2025-24012","summary":"Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability","details":"Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.","published":"2025-01-21T15:32:43.910Z","modified":"2026-07-15T01:49:06.391583220Z","cvss":{"score":4.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@umbraco-cms/backoffice","fixedVersion":"14.3.2"},{"ecosystem":"npm","name":"@umbraco-cms/backoffice","fixedVersion":"15.1.2"},{"ecosystem":"NuGet","name":"Umbraco.Cms.StaticAssets","fixedVersion":"14.3.2"},{"ecosystem":"NuGet","name":"Umbraco.Cms.StaticAssets","fixedVersion":"15.1.2"}],"fix":{"url":"https://github.com/umbraco/Umbraco-CMS/commit/d4f8754f933895b3a329296e25ddea6f84a0aea2","label":"umbraco/Umbraco-CMS@d4f8754"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24012.json"},{"type":"ADVISORY","url":"https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wv8v-rmw2-25wc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24012"},{"type":"FIX","url":"https://github.com/umbraco/Umbraco-CMS/commit/d4f8754f933895b3a329296e25ddea6f84a0aea2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.391583220Z"}}