CVE-2025-46736

MEDIUM

Umbraco <10.8.10, <13.8.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patched in versions 10.8.10 and 13.8.1. No known workarounds are available.

Scores

CVSS v3 5.3
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (2)
nuget/Umbraco.Cms 11.0.0-rc1 - 13.8.1NuGet
umbraco/umbraco_cms < 10.8.10
Published May 06, 2025
Tracked Since Feb 18, 2026