CVE-2026-46609

MEDIUM

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

Title source: cna
STIX 2.1

Description

Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0014
EPSS Percentile 3.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
nuget/Umbraco.Cms 14.0.0 - 17.4.0NuGet
umbraco/Umbraco-CMS >= 14.0.0, < 17.4.0
umbraco/umbraco_cms 14.0.0 - 17.4.0
Published Jun 10, 2026
Tracked Since Jun 10, 2026