Vulnerability record · CVE-2020-5810 · published 30 December 2020
CVE-2020-5810: Umbraco CMS stored XSS via malicious SVG media upload
Umbraco · Umbraco Cms
Umbraco CMS through 8.9.1 allows an authenticated user with media upload permission to upload a crafted .svg file that executes as a stored cross-site scripting payload. Because the payload persists in the CMS, it can fire for other users who view the media, making it a persistent client-side compromise rather than a one-off reflection.
Description
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires an authenticated upload-capable account and victim interaction, but the high EPSS and public exploit detail raise the practical risk for exposed Umbraco deployments.
What it is
Umbraco CMS through 8.9.1 allows an authenticated user with media upload permission to upload a crafted .svg file that executes as a stored cross-site scripting payload. Because the payload persists in the CMS, it can fire for other users who view the media, making it a persistent client-side compromise rather than a one-off reflection.
Impact
An attacker with a low-privileged media upload account can run script in the browser context of other CMS users, potentially stealing session data or performing actions as those users. The scope change in the CVSS vector indicates the injected script can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through the CMS media upload functionality; the attacker must be authenticated with permission to upload media, and the victim must view or interact with the uploaded SVG for the payload to execute.
Exploitation
No CISA KEV listing and no ransomware association; EPSS is high at roughly 0.62 (99th percentile), and the only references are Tenable advisories tagged Exploit, indicating public exploit detail exists but no confirmed in-the-wild activity is recorded here.
What to do
- Upgrade Umbraco CMS to a version later than 8.9.1 that addresses the SVG upload XSS.
- Restrict media upload permissions to trusted roles and review who currently holds them.
- Disallow or sanitize SVG uploads, or serve uploaded media with a restrictive Content-Type and Content-Disposition to prevent script execution.
- Apply a Content Security Policy that blocks inline and untrusted script execution in the CMS admin interface.
- Audit existing media library entries for suspicious SVG files and remove any found.
Detection
- Monitor media upload logs for .svg files, especially from accounts that rarely upload media.
- Inspect stored SVG files for embedded script elements, event handlers, or external references.
- Alert on CMS user sessions where script execution or unexpected outbound requests originate from media URLs.
- Review web server logs for requests to uploaded SVG paths followed by anomalous admin activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2020-59 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2020-59 | ExploitThird Party Advisory |
Track CVE-2020-5810 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5810), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.