Executive brief
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Affected products
- NuGet Umbraco.Cms
Junglewise Threat Intelligence
CVE-2025-48953 · Severity: low · CVSS 3.1 · Published 2025-06-04
Technologies: Umbraco.Cms (NuGet). Vendors: NuGet.
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads