A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.

Subscriptions

Vendors Products
Umbraco Subscribe
Umbraco Cms Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-52775 A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.
Github GHSA Github GHSA GHSA-572q-86rr-5vgq Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 31 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Umbraco
Umbraco umbraco Cms
CPEs cpe:2.3:a:umbraco:umbraco_cms:14.3.1:*:*:*:*:*:*:*
Vendors & Products Umbraco
Umbraco umbraco Cms

Wed, 12 Feb 2025 22:45:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.

Thu, 06 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 16:00:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-12T22:28:19.105Z

Reserved: 2024-12-06T00:00:00.000Z

Link: CVE-2024-55488

cve-icon Vulnrichment

Updated: 2025-01-22T17:40:35.872Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-22T16:15:29.770

Modified: 2025-12-31T14:51:51.553

Link: CVE-2024-55488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses