In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution. | |
| First Time appeared |
Umbraco
Umbraco forms |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:2.3:a:umbraco:forms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Umbraco
Umbraco forms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-16T19:00:26.430Z
Reserved: 2025-12-24T00:00:00.000Z
Link: CVE-2025-68924
Updated: 2026-01-16T19:00:19.293Z
Status : Received
Published: 2026-01-16T19:16:18.370
Modified: 2026-01-16T19:16:18.370
Link: CVE-2025-68924
No data.
OpenCVE Enrichment
No data.