Description
Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.
Recommendation
Update the @umbraco-cms/backoffice package to the latest compatible version. Followings are version details:
Affected version(s): **>= 15.0.0, < 15.1.2 >= 14.0.0, < 14.3.2** Patched version(s): **15.1.2 14.3.2**
References
Could your website be exposed too?
SmartScanner can check your website for XSS/HTML Injection Vulnerability in Umbraco Backoffice Components and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS) - CVE-2025-8101
- Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering - CVE-2025-54075
- QMarkdown Cross-Site Scripting (XSS) vulnerability - CVE-2025-43954
- gifplayer XSS vulnerability - CVE-2025-31128
You might also like:
See something that needs correcting? Let us knowUpdated January 21, 2025


