CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-67288

Critical · CVSS 10.0

Umbraco CMS — Arbitrary File Upload leading to Remote Code Execution (CWE-434)

CVSS
10.0
nvd
EPSS
0.50%
39th pct
KEV
No
Class
oss containerizable
CWE-434

Description

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.

Search profile — drives PoC discovery

Symbols Umbraco.Cmsfile uploadPDF file uploadcrafted PDFCVE-2023-49279file validationallowedUploadFilesdisallowedUploadFiles
Keywords CVE-2025-67288Umbraco CMS arbitrary file uploadUmbraco CMS RCE PDF uploadUmbraco file upload bypassUmbraco v16.3.3 exploitUmbraco CWE-434 PoCUmbraco unrestricted file uploadvuquyen03 CVE-2025-67288
Versions: 16.3.3

Affected packages

NuGet Umbraco.Cms 0 → ∞

References

Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-06T06:30:39.000Z