CVE-2026-46609

Source
https://cve.org/CVERecord?id=CVE-2026-46609
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46609.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46609
Aliases
Published
2026-06-10T15:59:03.416Z
Modified
2026-06-18T03:57:39.442740539Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
Details

Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46609.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "14.0.0"
        },
        {
            "fixed": "17.4.0"
        },
        {
            "introduced": "14.0.0"
        },
        {
            "fixed": "17.4.0"
        }
    ],
    "cpe": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46609.json"