← Back

CVE-2025-68924

nvd nist
Published: Jan 16, 2026Modified: Feb 20, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: MITRE (Secondary)

Description

In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

Affected (1)

1 product
Umbraco Forms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.13.16

References (3)

Source: cve@mitre.org
VDB EntryVendor AdvisoryMitigation

Timeline

No history available yet.