Andy Butland
14 exploits
Active since Jan 2025
Umbraco CMS <14.3.3 & Umbraco.Cms.Api.Management 15.0.0-rc1-15.2.3 - Authenticated Improper Authorization
CVSS 4.3
Umbraco CMS < 10.8.9 - Authenticated Improper Authorization via Backoffice API URL Manipulation
CVSS 4.9
Umbraco CMS 14.0.0-14.3.3 - Authenticated Path Traversal via Management API
CVSS 8.8
Umbraco <10.8.10, <13.8.1 - Info Disclosure
CVSS 5.3
Umbraco CMS 13.0.0-13.9.2, 15.0.0-15.4.1, 16.0.0-16.1.0 - Unauthorized Information Exposure via Content Delivery API
CVSS 5.3
Umbraco CMS 13.0.0-13.9.2, 15.0.0-15.4.1, 16.0.0-16.1.0 - Unauthorized Information Exposure via Content Delivery API
CVSS 5.3
Umbraco CMS 14.0.0-14.3.1 - Authenticated Cross-Site Scripting in Localized Backoffice Components
CVSS 4.6
Umbraco CMS <14.3.3 & Umbraco.Cms.Api.Management 15.0.0-rc1-15.2.3 - Authenticated Improper Authorization
CVSS 4.3
Umbraco CMS < 10.8.9 - Authenticated Improper Authorization via Backoffice API URL Manipulation
CVSS 4.9
Umbraco CMS 14.0.0-14.3.3 - Authenticated Path Traversal via Management API
CVSS 8.8
Umbraco <10.8.10, <13.8.1 - Info Disclosure
CVSS 5.3
Umbraco <15.4.2,16.0.0 - File Upload
CVSS 5.5
Umbraco CMS 13.0.0-13.9.2, 15.0.0-15.4.1, 16.0.0-16.1.0 - Unauthorized Information Exposure via Content Delivery API
CVSS 5.3
Umbraco CMS 10.0.0-13.12.0 - Authenticated Arbitrary File Existence Enumeration via Dictionary Upload
CVSS 4.9