← back
CVE-2026-46609mediumCWE-79

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.6epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected products
umbraco · Umbraco-CMS