PT-2026-42647 · Nuget · Umbraco Cms

Published

2026-05-21

·

Updated

2026-05-21

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Impact

Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.

Patches

This issue has been patched in 17.4.0

Fix

XSS

Weakness Enumeration

Related Identifiers

GHSA-VR9V-27GG-QGX4

Affected Products

Umbraco Cms