Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 13, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 13, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 13, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 13, 2025

      This $4 Steam Deck game includes the most-played classics from my childhood — and it will save you paper

      May 13, 2025

      Microsoft shares rare look at radical Windows 11 Start menu designs it explored before settling on the least interesting one of the bunch

      May 13, 2025

      NVIDIA’s new GPU driver adds DOOM: The Dark Ages support and improves DLSS in Microsoft Flight Simulator 2024

      May 13, 2025

      How to install and use Ollama to run AI LLMs on your Windows 11 PC

      May 13, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Community News: Latest PECL Releases (05.13.2025)

      May 13, 2025
      Recent

      Community News: Latest PECL Releases (05.13.2025)

      May 13, 2025

      How We Use Epic Branches. Without Breaking Our Flow.

      May 13, 2025

      I think the ergonomics of generators is growing on me.

      May 13, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      This $4 Steam Deck game includes the most-played classics from my childhood — and it will save you paper

      May 13, 2025
      Recent

      This $4 Steam Deck game includes the most-played classics from my childhood — and it will save you paper

      May 13, 2025

      Microsoft shares rare look at radical Windows 11 Start menu designs it explored before settling on the least interesting one of the bunch

      May 13, 2025

      NVIDIA’s new GPU driver adds DOOM: The Dark Ages support and improves DLSS in Microsoft Flight Simulator 2024

      May 13, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-47280 – Umbraco Forms Email Injection Vulnerability

    CVE-2025-47280 – Umbraco Forms Email Injection Vulnerability

    May 13, 2025

    CVE ID : CVE-2025-47280

    Published : May 13, 2025, 5:16 p.m. | 1 hour, 48 minutes ago

    Description : Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and 15.1.2, the ‘Send email’ workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address, potentially bypassing spam and email client security systems. This issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. Unpatched or unsupported versions can workaround this issue by using the `Send email with template (Razor)` workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the `SendEmail` workflow type can be removed using a composer available in the GitHub Security Advisory for this vulnerability.

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-4658 – OpenPubkey/OPKSSH JWS Signature Verification Bypass
    Next Article CVE-2025-3757 – OpenPubkey Invalid JWS Signature Verification

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-45858 – TOTOLINK A3002R Command Injection Vulnerability

    May 13, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-29840 – Windows Media Stack-based Buffer Overflow Remote Code Execution

    May 13, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    The Elder Scrolls 4: Oblivion Remastered review roundup — Here’s what critics had to say for this remastered edition of one of Bethesda’s classic RPGs

    News & Updates

    Atomfall: How to open District A and get inside the Medical Facility

    News & Updates

    I used ChatGPT to translate image text when Google’s tool failed me – and things got weird

    News & Updates

    UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

    Development

    Highlights

    Development

    SugarGh0st RAT Campaign Targets U.S. AI Experts

    May 17, 2024

    Researchers have identified a recent cyber espionage campaign by a China-linked threat actor dubbed “UNK_SweetSpecter,”…

    Character AI Releases Prompt Poet: A New Low Code Python Libary that Streamlines Prompt Design for both Developers and Non-Technical Users

    August 4, 2024

    Il tasto Copilot delle nuove tastiere verrà supportato dal kernel Linux, ma ci sono diverse questioni di sicurezza da considerare

    February 6, 2025

    Tiling Shell’s Newest Feature Speeds Up Window Snapping

    January 12, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.