CVE-2025-67288
Critical · CVSS 10.0Umbraco CMS — Arbitrary File Upload leading to Remote Code Execution (CWE-434)
- CVSS
- 10.0
- nvd
- EPSS
- 0.50%
- 39th pct
- KEV
- No
- Class
- oss containerizable
- CWE-434
Description
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.
Search profile — drives PoC discovery
Symbols Umbraco.Cmsfile uploadPDF file uploadcrafted PDFCVE-2023-49279file validationallowedUploadFilesdisallowedUploadFiles
Keywords CVE-2025-67288Umbraco CMS arbitrary file uploadUmbraco CMS RCE PDF uploadUmbraco file upload bypassUmbraco v16.3.3 exploitUmbraco CWE-434 PoCUmbraco unrestricted file uploadvuquyen03 CVE-2025-67288
Versions: 16.3.3
Affected packages
| NuGet | Umbraco.Cms | 0 → ∞ |
References
Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-06T06:30:39.000Z