CVE detail
CVE-2024-35239 — CVE-2024-35239
Published 2024-05-28 · Modified 2026-06-17 · Vendor umbraco · Product umbraco_forms · Source nvd
LOW
severity
CVSS-derived band
0.0034
EPSS probability
exploitation probability, 30d
27.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References