Remote Code Execution Vulnerability in UmbracoForms by Umbraco
CVE-2025-68924
7.5HIGH
What is CVE-2025-68924?
In UmbracoForms versions up to 8.13.16, a security flaw exists that allows authenticated attackers to supply a malicious WSDL (Web Service Description Language) URL as a data source. This may lead to the potential execution of arbitrary code on the server, posing risks to data integrity and system security. Users of affected versions are advised to update to the latest version to mitigate these risks.
Affected Version(s)
Forms 0 <= 8.13.16
