CVE-2026-46609
MEDIUM
NVD
CVSS Score
4.6
Severity
MEDIUM
Published
Jun 10, 2026
Vendor
unknown
Description
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.