Arbitrary File Upload Vulnerability in Umbraco CMS from Umbraco
CVE-2025-67288
10CRITICAL
What is CVE-2025-67288?
An arbitrary file upload vulnerability in Umbraco CMS version 16.3.3 allows malicious users to upload crafted PDF files, enabling them to execute unauthorized code on the server. This exposure can lead to significant security breaches, making it essential for organizations using this CMS to assess their systems and implement immediate mitigation strategies.
