CVE-2025-48953

Source
https://cve.org/CVERecord?id=CVE-2025-48953
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48953.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-48953
Aliases
Published
2025-06-03T18:19:28.771Z
Modified
2026-04-10T05:28:52.872638Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Details

Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file that doesn't adhere with the configured allowable file extensions via a manipulated API request. The issue is patched in versions 15.4.2 and 16.0.0. No known workarounds are available.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48953.json"
}
References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48953.json"