-
CVSS Score
-The vulnerability stems from missing HTML encoding in two key UI rendering flows. The commit fe2b86b explicitly adds Server.HtmlEncode() to both locations:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| UmbracoCMS.Web | nuget | < 7.7.3 | 7.7.3 |