Installs Umbraco CMS with all default dependencies in your ASP.NET Core project.
97%
Total Score
100
83
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-46609 Umbraco.Cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 14.0.0 - 17.3.5. | 14.0.0 - 17.3.5 | Medium |
CVE-2026-46616 Umbraco.Cms is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 13.14.0 and 17.3.0-rc - 17.4.0. | 0.0.0 - 13.14.017.3.0-rc - 17.4.0 | Medium |
CVE-2026-31834 Umbraco.Cms is vulnerable to Improper Privilege Management in versions 15.3.1 - 16.5.1 and 17.0.0 - 17.2.2. | 15.3.1 - 16.5.117.0.0 - 17.2.2 | High |
CVE-2026-31833 Umbraco.Cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 16.2.0 - 16.5.1 and 17.0.0 - 17.2.1. | 16.2.0 - 16.5.117.0.0 - 17.2.1 | Medium |
CVE-2026-31832 Umbraco.Cms is vulnerable to Authorization Bypass Through User-Controlled Key in versions 14.0.0 - 16.5.1 and 17.0.0 - 17.2.2. | 14.0.0 - 16.5.117.0.0 - 17.2.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
umbraco.cms.imaging.imagesharp Version [13.16.1, 14.0.0) | — | — |
umbraco.cms.persistence.efcore.sqlite Version [13.16.1, 14.0.0) | — | — |
umbraco.cms.persistence.efcore.sqlserver Version [13.16.1, 14.0.0) | — | — |
umbraco.cms.persistence.sqlite Version [13.16.1, 14.0.0) | — | — |
umbraco.cms.persistence.sqlserver Version [13.16.1, 14.0.0) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant