← Back to browse · API

CVE-2025-67288

Severity
CRITICAL
CVSS
10.0
EPSS
0.00522
Risk score
40.18
CISA KEV
No
PoC
No
Published
2025-12-22
Modified
2026-07-08
First seen
2026-08-07
Aliases
EUVD-2025-204737, GHSA-54MJ-VCVJ-Q3V5
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-204737

Description

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. The Supplier also states that PDF JavaScript runs in a completely isolated sandbox, not the browser's DOM context, which means that privilege boundaries would not be crossed, a related issue to CVE-2023-49279.

References