
[Updated] Security Advisory, April 8 , 2025 - Patches for Umbraco CMS are now available
We recommend you upgrade to the latest patch

Important Update, April 11, 2025: The severity of the vulnerability described below has been re-evaluated and upgraded from moderate to high. The patch released on April 8, 2025, still fully resolves the issue. The impact section below has been updated accordingly.
Who’s affected?
This vulnerability affects:
-
Umbraco 14.0.0 - 14.3.3
-
Umbraco 15.0.0 - 15.3.0
How to fix the vulnerability
Patches are available for the latest minor on each supported major version. Sites will need to update to the latest minor version before the patch can be applied. As we are looking at a patch upgrade, and the fix is straightforward, we expect the patch upgrade to only require minimal effort per project.
Instructions on patch availability and how to upgrade can be found in the release notes:
Automatic fix on Umbraco Cloud
All Umbraco Cloud sites running the latest minor version of a supported version are patched via the automated patch feature. The security patches will be rolled out to Umbraco Cloud today to ensure all sites have been fixed.
If a project is not running the latest minor version (14.3.x, 15.3.x), the patch can be applied using the minor upgrade feature.
ℹ️ Note that Umbraco Cloud also supports automated minor upgrades. This can be enabled on a per-project level and ensures you're always ready to receive the latest patch.
What we know about the vulnerability
For more details, please refer to the security advisory.
There are no indications that the vulnerabilities were discovered or exploited prior to the report. Further details will be published on the Security Advisories at a later date.
Impact
The vulnerabilities all require authenticated access to the backoffice, meaning an attacker must first log in to the backoffice to exploit them. This results in an overall moderatehigh-severity rating. Nevertheless, we recommend updating to the latest patched version to ensure optimal security.
Update, April 11, 2025: The severity of the vulnerability described below has been re-evaluated and upgraded from moderate to high. This is not based on a widening of the vulnerability to non-authenticated users but a recognition of the ability of a malicious or compromised user to upload files to non-permitted locations and the impact that could cause. The patch released on April 8, 2025, still fully resolves the issue.
Credit
We would like to thank Kevin Joensen from Baldur for the responsible disclosure of the issue they discovered.
Any questions?
If you have any questions or comments about this advisory, make sure to get in touch with us directly on the Security Advisories. Alternatively, you can reach out to the dedicated security email address listed at https://umbraco.com/security. Here you can also find information on how we handle security-related issues.
📨 For direct communication related to security in Umbraco products, please sign up for the dedicated security mailing list.