PT-2025-52674 · Umbraco · Umbraco Cms

Vuquyen03

·

Published

2025-12-22

·

Updated

2026-01-02

·

CVE-2025-67288

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Umbraco CMS version 16.3.3
Description An arbitrary file upload issue exists in Umbraco CMS version 16.3.3. Attackers can potentially execute arbitrary code by uploading a specially crafted PDF file. The supplier disputes responsibility, stating file validation is the system administrator's responsibility.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

RCE

XSS

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-67288
GHSA-54MJ-VCVJ-Q3V5

Affected Products

Umbraco Cms