Umbraco CMS 13 (LTS)
Umbraco CMS 13 (LTS)
The Umbraco CMS 13 (LTS) reaches end of service life on Dec 14, 2026. Third-party support keeps it managed past that date — issue management, vulnerability remediation, and compliance maintenance from 24/7 engineers.
24/7 engineers own your Umbraco CMS 13 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- umbraco
- release
- 13
- product Label
- Umbraco CMS
- release Label
- 13 (LTS)
- codename
- lts
- true
- latest Version
- 13.16.1
- release Date
- 2023-12-14
- maintained
- true
- source Url
- https://endoflife.date/umbraco
Lifecycle Dates
- End of Service Life
- Dec 14, 2026
- Last OEM Support
- Dec 14, 2025
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Umbraco CMS 13 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Umbraco CMS 13 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Umbraco CMS 13 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Umbraco CMS 13 (LTS) Support: Frequently Asked Questions
Is the Umbraco CMS 13 (LTS) still supported?
Yes, but Umbraco CMS support for the Umbraco CMS 13 (LTS) ends on Dec 14, 2026. You can upgrade on the vendor's schedule, or move to third-party support and keep the release you're on — issues managed, vulnerabilities remediated, compliance maintained.
When is the Umbraco CMS 13 (LTS) end of service life (EOSL) date?
Umbraco CMS lists the end of service life for the Umbraco CMS 13 (LTS) as Dec 14, 2026.
Can I keep using the Umbraco CMS 13 (LTS) after its EOSL date?
Yes. EOSL means Umbraco CMS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Umbraco CMS 13 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Umbraco CMS 13 (LTS)
13 published CVEs affect the Umbraco CMS 13 (LTS). Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-34071 | MEDIUM | 6.1 | May 21, 2024 | Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1. |
| CVE-2026-46616 | MEDIUM | 5.4 | Jun 10, 2026 | Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. This issue has been patched in versions 13.14.0 and 17.4.0. |
| CVE-2025-54425 | MEDIUM | 5.3 | Jul 30, 2025 | Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restricted from public access where an API key must be provided in a header to authorize the request. It's also possible to configure output caching, such that the delivery API outputs will be cached for a period of time, improving performance. There's an issue when these two things are used together, where caching doesn't vary by the header that contains |
| CVE-2025-49147 | MEDIUM | 5.3 | Jun 24, 2025 | Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request to an anonymously authenticated endpoint it's possible to retrieve information about the configured password requirements. The information available is limited but would perhaps give some additional detail useful for someone attempting to brute force derive a user's password. This information was not exposed in Umbraco 7 or 8, nor in 14 o |
| CVE-2025-46736 | MEDIUM | 5.3 | May 6, 2025 | Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patched in versions 10.8.10 and 13.8.1. No known workarounds are available. |
| CVE-2025-66625 | MEDIUM | 4.9 | Dec 9, 2025 | Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to temporary file paths. The application’s error responses (HTTP 500 when a file exists, 404 when it does not) allow the attacker to enumerate the existence of arbitrary files on the server’s filesystem. This vulnerability does not allow reading or writing file contents |
| CVE-2025-27602 | MEDIUM | 4.9 | Mar 11, 2025 | Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. The issue is patched in versions 10.8.9 and 13.7.1. No known workarounds are available. |
| CVE-2024-48927 | MEDIUM | 4.6 | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue. As a workaround, derver-side file validation is available to strip script tags from file's content during the file upload |
| CVE-2025-27601 | MEDIUM | 4.3 | Mar 11, 2025 | Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section. The issue is patched in versions 15.2.3 and 14.3.3. No known workarounds are available. |
| CVE-2024-48929 | MEDIUM | 4.2 | Oct 22, 2024 | Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7, during an explicit sign-out, the server session is not fully terminated. Versions 13.5.2 and 10.8.7 contain a patch for the issue. |
| CVE-2024-48926 | MEDIUM | 4.2 | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue. |
| CVE-2024-35218 | MEDIUM | 4.2 | May 21, 2024 | Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. This vulnerability has been patched in version(s) 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer. |
| CVE-2024-29035 | MEDIUM | 4.1 | Apr 17, 2024 | Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1. |