CVE-2021-47776

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:umbraco:umbraco_cms:8.14.1:*:*:*:*:*:*:*

History

23 Jan 2026, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:umbraco:umbraco_cms:8.14.1:*:*:*:*:*:*:*
References () https://our.umbraco.com/ - () https://our.umbraco.com/ - Product
References () https://releases.umbraco.com/all-releases - () https://releases.umbraco.com/all-releases - Release Notes
References () https://www.exploit-db.com/exploits/50462 - () https://www.exploit-db.com/exploits/50462 - Exploit, VDB Entry
First Time Umbraco
Umbraco umbraco Cms

15 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 16:16

Updated : 2026-01-23 18:06


NVD link : CVE-2021-47776

Mitre link : CVE-2021-47776

CVE.ORG link : CVE-2021-47776


JSON object : View

Products Affected

umbraco

  • umbraco_cms
CWE
CWE-918

Server-Side Request Forgery (SSRF)