Articles tagged #security


UMB.FYI
2026-09-02

📰 Umbraco CSP Nonces with Output Caching - Part 3

Justin Neville discusses the challenge of implementing both a strict Content Security Policy (CSP) with nonces and output caching on the Nevitech website. He presents a solution involving middleware that replaces nonce placeholders in cached HTML and rewrites CSP headers, ensuring consistency and functionality without sacrificing either feature.

📺 umbraCoffee - Back To School

In this episode of #umbraCoffee, hosts Marcin and Callum discuss the transition back to school, productivity impacts of summer breaks, and busy work schedules. They also delve into AI integration in development, community support, and the need for secure solutions within the Umbraco community.

UMB.FYI
2026-08-19

📰 Security Advisory: Security Patches for Umbraco CMS, Umbraco Forms, and Umbraco AI now available

Anders Nis Herforth Larsen reports four vulnerabilities in Umbraco CMS, Forms, and AI, including one high-severity issue. Patches are available for affected versions, and users are urged to upgrade. Notably, Umbraco 14, 15, and 16 will not receive patches. Mitigation strategies are provided for those unable to upgrade immediately.

UMB.FYI
2026-07-29

📰 Security Patches for Umbraco Forms are now available

A high-level security vulnerability in Umbraco Forms versions 13, 17, and 18 has been identified and patched. Users are advised to upgrade to the latest versions to mitigate risks, as unsupported versions remain vulnerable. The flaw allows unauthenticated users to bypass submission safeguards. Automatic upgrades are available for Umbraco Cloud users.

UMB.FYI
2026-07-08

📰 Security Advisory, July 7, 2026: Security Patches are now available

A high-severity vulnerability affecting Umbraco versions 13.0.0 - 13.15.0, 17.0.0 - 17.5.2, and 18.0.0 - 18.0.1 has been identified and patched. Users are advised to upgrade to supported versions. The vulnerability allows unauthorized content retrieval via the delivery API. Thanks to Ardya Suryadinata for reporting the issue.

UMB.FYI
2026-06-10

📰 Umbraco.AI Security Advisory, June 4, 2026

Matt Brailsford announces a security patch for the Umbraco.AI package, addressing a vulnerability in versions 1.0.0 through 1.13.x. Users are urged to update to version 1.14.0 or later. The patch enforces strict configuration reference resolution, enhancing security by restricting access to sensitive information. Further details are available in the GitHub Security Advisory.

📦 BlendInteractive.Umbraco.SecurityDashboard

The Umbraco Security Dashboard is a package that provides a dashboard within the Umbraco backoffice to help identify potential security vulnerabilities in installed packages.

UMB.FYI
2026-05-27

📦 M1sterPl0w.Umbraco.AccessRestriction

An Umbraco package that restricts access to your site (or specific paths) by IP address whitelist.

UMB.FYI
2026-05-20

📰 AI on Your Terms: How Umbraco Reimagines AI

At Digital Excellence 2026, Jeppe Birkebæk Truelsen demonstrated how Umbraco enables membership organizations to scale content while maintaining brand voice and data security. By implementing a governance layer for AI, organizations can define boundaries and retain control, ensuring AI acts as an assistant rather than a decision-maker, fostering accountability and trust.

📦 HCS.Passwordless.WebAuthn

WebAuthn/FIDO2 passkey add-on for Umbraco 17 passwordless member authentication.

📦 HCS.Passwordless.Otp

One-time password (OTP) email add-on for Umbraco 17 passwordless member authentication.

UMB.FYI
2026-05-13

📰 Carlini-style software vulnerability hunting, on a budget

Nicholas Carlini discussed using Anthropic's Claude models for automated vulnerability discovery in software. Liam Laverty replicated this approach in the Umbraco-CMS repository using a heuristics-based method, achieving significant cost reduction—under $20 compared to Carlini's $40k—while identifying potential vulnerabilities and improving documentation, although no CVEs were found.

UMB.FYI
2026-05-06

📰 Umbraco Member thrown out after changing password

The migration of the Newsletter Studio website from Umbraco 8 to Umbraco 17 revealed a security feature that logs out members upon password changes. This occurs due to the default settings preventing concurrent logins. Solutions include refreshing the login cookie after a password change or enabling concurrent logins in appsettings.json.

UMB.FYI
2026-04-29

📰 UmBackdoor

In a recent blog post, the author reflects on the UmBackdoor, a proof-of-concept Umbraco package created in 2019. The package allowed attackers to install a backdoor for remote access via a reverse shell. The author discusses various password reset techniques and emphasizes the importance of security measures to prevent such exploits.

UMB.FYI
2026-04-22

📦 uBrokenWindow

Generate a new backoffice user account on application startup. Use with care!

UMB.FYI
2026-03-11

📰 Umbraco CMS Security Advisory, March 10, 2026

Andy Butland outlines security patches for Umbraco versions 16.0.0 - 16.5.0 and 17.0.0 - 17.2.1, addressing three vulnerabilities: vertical privilege escalation, XSS injection, and unauthorized domain data modification. Users are urged to upgrade to secure their CMS, with automatic fixes available for Umbraco Cloud projects.

📰 Securing Umbraco Images with HMAC

Nathaniel Nunes discusses the security risks associated with Umbraco's image processing capabilities, particularly the potential for unrestricted image manipulation leading to server overload. He recommends implementing HMAC authentication to secure image requests, detailing how to configure it in Razor and Next.js environments. Nunes emphasizes the importance of safeguarding the HMAC key and mentions upcoming security checks in Umbraco 17.3.0.

UMB.FYI
2026-02-04

📰 Mitigating CVE-2025-67288 in Umbraco 13 (if you feel you need to)

Jason Elkin critiques CVE-2025-67288, arguing it misrepresents Umbraco's security regarding PDF uploads with embedded JavaScript. He asserts that Umbraco does not process such files for remote code execution or XSS vulnerabilities. Elkin proposes implementing an IFileStreamSecurityAnalyzer to enhance file safety checks, mitigating potential risks effectively.

📰 Handling editor-injected JavaScript in Umbraco v17 with Umbraco Community CSPManager

Debasish Gracias discusses implementing a Content Security Policy (CSP) for Umbraco v17, focusing on allowing editors to embed JavaScript securely. He outlines a method to automatically inject CSP nonces into editor-supplied script tags, ensuring compliance with strict CSP settings while maintaining flexibility for content creators.

UMB.FYI
2026-01-28

📰 Top 10 Umbraco Security Vulnerabilities that You Must know in 2026

Keyur Garala outlines critical Umbraco security vulnerabilities for 2026, emphasizing the importance of regular updates, strong authentication, and proper user permissions. He highlights risks from outdated software, insecure plugins, and misconfigured environments. To safeguard against cyber threats, Garala advocates for consistent security practices and partnering with Arroact for professional support.

1 2 3
UMB.FYI
Archive Polls Pulse Tips Firehose Privacy About

UMB.FYI is built with ❤ by the Umbraco community and is not affiliated with Umbraco HQ