- Description
- An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.
- Source
- cve@mitre.org
- NVD status
- Modified
- CNA Tags
- disputed
- Products
- umbraco_cms
CVSS 3.1
- Type
- Primary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-434
- Hype score
- Not currently trending
🚨 CVE-2025-67288: CRITICAL vuln in Umbraco CMS 16.3.3 allows attackers to upload malicious PDFs & execute code remotely. Patch pending—tighten file upload controls now! https://t.co/94IUt3vdNa #OffSeq #Umbraco #CyberSecurity https://t.co/1feAiL0j14
@offseq
23 Dec 2025
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67288 Arbitrary File Upload Remote Code Execution in Umbraco CMS v16.3.3 https://t.co/wTsWeLdc2V
@VulmonFeeds
22 Dec 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CVE-2025-67288 - Critical An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. https://t.co/Pll49ReCCX https://t.co/wD8caLjQX7
@TheHackerWire
22 Dec 2025
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:umbraco:umbraco_cms:16.3.3:*:*:*:*:*:*:*",
"matchCriteriaId": "3219BD08-2A93-46BC-847C-493BE4220357",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]