{"id":"CVE-2025-24012","summary":"Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability","details":"Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.","aliases":["GHSA-wv8v-rmw2-25wc"],"modified":"2026-08-12T03:51:39.053135682Z","published":"2025-01-21T15:32:43.910Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24012.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24012.json"},{"type":"ADVISORY","url":"https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wv8v-rmw2-25wc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24012"},{"type":"FIX","url":"https://github.com/umbraco/Umbraco-CMS/commit/d4f8754f933895b3a329296e25ddea6f84a0aea2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/umbraco/umbraco-cms","events":[{"introduced":"8685c7d64a1c597983cfb82e1bd1d269d22e4508"},{"fixed":"abc312c9b45440c0f311dc95354db0949dbf9808"},{"introduced":"76ed1707537e8f0dcf13ae7a84d2af60d1aa1816"},{"fixed":"559c6c9f312df1d6eb1bde82c4b81c0896da6382"},{"fixed":"d4f8754f933895b3a329296e25ddea6f84a0aea2"}],"database_specific":{"cpe":"cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"14.0.0"},{"fixed":"14.3.2"},{"introduced":"15.0.0"},{"fixed":"15.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24012.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}]}