← Vulnerability feed

Vulnerability record · CVE-2020-7685 · published 28 July 2020

CVE-2020-7685: Umbraco forms insecure default initialization vulnerability

Umbraco · Umbraco Forms

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.

7.5 CVSS 3.1 High EPSS 0.90% · top 41.9% CWE-1188 · Insecure default initialization
7.5CVSS 3.1 base score, v2 5.0
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7685 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33224Umbraco forms unrestricted file upload vulnerabilityFile upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.EPSS 0.73%7.5CVE-2025-68924Umbraco forms inclusion from untrusted sphere vulnerabilityIn Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code …EPSS 0.77%6.0CVE-2026-24687Umbraco forms path traversal vulnerabilityUmbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enu…EPSS 0.46%5.4CVE-2024-35239Umbraco forms cross-site scripting vulnerabilityUmbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject uns…EPSS 0.34%5.3CVE-2025-23041Umbraco forms improper input validation vulnerabilityUmbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are va…EPSS 0.38%2.3CVE-2025-47280Umbraco forms vulnerabilityUmbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 a…EPSS 0.29%5.3CVE-2025-48927TeleMessage Spring Boot Actuator heap dump endpoint exposed by insecure defaultTeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initi…KEVEPSS 11%analysed9.8CVE-2023-27524Apache Superset default SECRET_KEY allows session forgery and auth bypassApache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cook…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2020-7685), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.