Umbraco.Cms is vulnerable to Cross-site Scripting (XSS)
40
Medium Risk
Affected versions of this package are vulnerable to Cross-site scripting (XSS) via unsanitized URL injection in the history.pushState function. The vulnerability occurs when window.location.href is directly embedded into the HTML template without proper encoding, allowing attackers to craft malicious URLs containing JavaScript payloads. When a victim visits a manipulated link (e.g., https://victim.site/?"></script><script>alert(document.cookie)</script>), the payload executes within the application context, enabling session hijacking, data theft, or malicious actions.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms is vulnerable to Cross-site Scripting (XSS) in versions 15.3.0 - 16.0.0.
Upgrade the Umbraco.Cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant