{"id":"CVE-2024-55488","details":"A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.","modified":"2026-08-12T03:51:35.731420072Z","published":"2025-01-22T00:00:00Z","database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55488.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://docs.umbraco.com/umbraco-cms/develop-with-umbraco/templating-and-rendering/design/stylesheets-javascript"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55488.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55488"},{"type":"ADVISORY","url":"https://www.nccgroup.com/us/research-blog/technical-advisory-cross-site-scripting-in-umbraco-rich-text-display/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/umbraco/umbraco-cms","events":[{"introduced":"6caf53ed2e62762ae07f2b8a73403f30594b42fa"},{"last_affected":"6caf53ed2e62762ae07f2b8a73403f30594b42fa"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:umbraco:umbraco_cms:14.3.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"14.3.1"},{"last_affected":"14.3.1"}]}}],"versions":["14.3.1","release-14.3.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55488.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}