The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Umbraco.Cms.Web.Common to version 13.15.1, 17.5.3, 18.0.2 or higher.
Umbraco.Cms.Web.Common is a package containing the web assembly needed to run Umbraco CMS.
Affected versions of this package are vulnerable to Missing Authorization in the Content Delivery API, which enforces Public Access protection only on directly requested nodes, expanding Content Picker and Multi-Node Tree Picker references without validating access to the referenced node and without applying the content type alias restrictions. An attacker can read protected content, obtaining names, routes, and IDs in all cases and full property values when using ?expand, by requesting a public node that references the protected one, including through pickers nested inside Block List, Block Grid, or Rich Text Editor properties. This requires a public node to reference protected content and the Delivery API to be reachable, typically with DeliveryApi:PublicAccess: true, and a direct request for the protected node still returns 401, which masks the exposure from anyone testing the node directly.