Description
Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.
Recommendation
Update the @umbraco-cms/backoffice package to the latest compatible version. Followings are version details:
Affected version(s): **>= 15.0.0, < 15.1.2 >= 14.0.0, < 14.3.2** Patched version(s): **15.1.2 14.3.2**
References
Related Issues
- Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS) - CVE-2025-8101
- Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering - CVE-2025-54075
- QMarkdown Cross-Site Scripting (XSS) vulnerability - CVE-2025-43954
- gifplayer XSS vulnerability - CVE-2025-31128
You might also like:
- Tags:
- npm
- @umbraco-cms/backoffice
Anything's wrong? Let us know Last updated on January 21, 2025


