We've published the following Security Advisories:
Umbraco CMS
Relevant for everyone using the Umbraco CMS and for Umbraco Cloud users - Umbraco Cloud users are, however, often patched automatically and don't need to take further action.
- 2024, May 21: https://umbraco.com/blog/security-advisory-may-21-2024-patch-is-now-available/
- 2023, Dec 12: https://umbraco.com/blog/security-advisory-security-patches-for-umbraco-8-10-11-and-12-now-available/
- 2023, Jul 13: https://umbraco.com/blog/security-advisory-july-13-2023-security-patches-for-umbraco-cms-are-available/
- 2023, Mar 21: https://umbraco.com/blog/security-advisory-march-21-2023-patch-is-now-available/
(Updated with additional information and new patches on March 28, 2023) - 2022, Sep 6: https://umbraco.com/blog/security-advisory-september-6-2022-patch-is-now-available/
- 2022, Jan 20: https://umbraco.com/blog/security-advisory-january-20-2022-medium-severity-security-vulnerability-identified-in-umbraco-cms/
- 2019, Dec 10: https://umbraco.com/blog/security-advisory-10th-december-2019/
- 2019, July 30: https://umbraco.com/blog/security-advisory-july-30th-2019-patch-available/
- 2019, July 9: https://umbraco.com/blog/security-advisory-july-9th-2019/
- 2016, Mar 1: https://umbraco.com/blog/major-security-vulnerability-patched-in-umbraco-versions-450-through-4711/
- 2014, Jul 21: https://umbraco.com/blog/security-issues-found-in-umbraco-4-6-and-7/
- 2014, May 23: https://umbraco.com/blog/security-update-one-more-major-issue-fixed-in-470-through-4711/
- 2013, May 1: https://umbraco.com/blog/security-update-two-major-vulnerabilities-found/
- 2013, Apr 29: https://umbraco.com/blog/security-vulnerability-found-immediate-action-recommended/
- 2012, Nov 14: https://umbraco.com/blog/security-update-for-4100/
ClientDependency
ClientDependency is a module that ships with Umbraco CMS.
- 2020, Mar 17: https://umbraco.com/blog/security-advisory-17th-of-march-patch-for-your-site-is-now-available/
- 2017, Feb 16: https://umbraco.com/blog/security-advisory-update-clientdependency-immediately/
- 2015, Feb 5: https://umbraco.com/blog/security-alert-update-clientdependency-immediately/
Umbraco Forms
Umbraco Forms is an optional plugin for Umbraco, maintained by Umbraco HQ.
- 2021, Jul 20: https://umbraco.com/blog/security-advisory-20th-of-july-2021-patch-is-now-available/
- 2020, Mar 24: https://umbraco.com/blog/security-advisory-forms-version-8/
- 2018, May 15: https://umbraco.com/blog/umbraco-forms-security-update/
- 2017, Feb 28: https://umbraco.com/blog/security-advisory-update-umbraco-forms-immediately/
- 2016, Jan 27: https://umbraco.com//blog/umbraco-forms-security-notice/
Umbraco Workflow
- 2024, April 23: Umbraco.Workflow.Issues/security/advisories/GHSA-287f-46j7-j4wh