CVE-2026-31833 | Umbraco CMS up to 16.5.0/17.2.0 Setting cross site scripting (GHSA-vrqc-59mw-qqg7)
A vulnerability labeled as problematic has been found in Umbraco CMS up to 16.5.0/17.2.0. Affected is an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-31833. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.