CVE-2025-47280: Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
The ‘Send email’ workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems).
References
Code Behaviors & Features
Detect and mitigate CVE-2025-47280 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →