← Back

CVE-2026-31833

nvd nist
Published: Mar 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Exploitability: 1.2 / Impact: 5.5
Source: security-advisories@github.com (Secondary)

Description

Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify instance, event handler attributes such as onclick and onload, when used within Umbraco web components (umb-*, uui-*, ufm-*) were not filtered. This vulnerability is fixed in 16.5.1 and 17.2.2.

Affected (2)

Products: Umbraco: Umbraco Cms
1 product
Umbraco Cms
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Umbraco
From 16.2.0 to 16.5.1
From 17.0.0 to 17.2.2

References (1)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.