ASP.NET CMS File Upload Vulnerability in Umbraco by Umbraco
CVE-2025-48953
5.5MEDIUM
What is CVE-2025-48953?
Umbraco, an ASP.NET content management system, has a vulnerability that allows unauthorized file uploads through manipulated API requests. This flaw impacts versions 14.0.0 and earlier, making it possible for attackers to bypass configured allowable file extensions, exposing the system to potential threats. Users are advised to update to versions 15.4.2 or 16.0.0 to mitigate the risk, as no workarounds are available for earlier versions.
Affected Version(s)
Umbraco-CMS >= 14.0.0, < 15.4.2