CVE-2025-23041 Details
Description
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
A vulnerability exists in Umbraco.Forms versions through 10.5.7 and prior to 8.13.16, allowing character limits set by editors for short and long answer fields to be validated only on the client side, with no server-side enforcement. This could lead to fields being submitted with excessive characters, potentially causing issues downstream. The vulnerability arises because the framework does not properly validate input lengths on the server, leaving room for overlong submissions that could disrupt application functionality.
Users are advised to upgrade to Umbraco.Forms versions 8.13.16, 10.5.7, 13.2.2, or 14.1.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-9v8m-qv22-f268 | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| umbraco umbraco forms | < 8.13.15 >= 10.0.0, < 10.5.7 >= 13.0.0, < 13.2.2 >= 14.0.0, < 14.1.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 19, 2025 | Initial Analysis | [email protected] |
| Jan 14, 2025 | New CVE Received | [email protected] |