May 2025: the patch you could not apply until you upgraded first

· JD + AI · Umbraco

May 2025: the patch you could not apply until you upgraded first

On 6 May 2025 Umbraco published a moderate-severity advisory: login response timing leaked enough information to enumerate valid usernames. Versions 10.0.0 through 10.8.9 and 13.0.0 through 13.8.0 were affected, and the fixes shipped as 10.8.10 and 13.8.1. That is the whole month in one item, and the interesting part is not the vulnerability.

The advisory assumes you already did the upgrade you have been postponing

The advisory, written by Andy Butland on Umbraco's own blog, is explicit about the shape of the fix: "Patches are available for the latest minor on each supported major version." If you were running 13.4, there was no 13.4.x patch waiting for you. You did the minor upgrade first, then took the patch. On a site that has not moved in eighteen months, that is not a fifteen-minute job, and it is the reason a moderate advisory can still eat a sprint.

Umbraco Cloud projects on the latest minor were patched automatically the same day. Projects behind on minors were not, and had to use the minor upgrade feature to get there. Unsupported majors get no patch at all, which is the sentence to forward to whoever is still running 8.

Umbraco credits three reporters from NTNU Gjøvik and states there is no evidence of exploitation before disclosure. This is a vendor-official source for the version numbers above, which is the standard we hold: do not take a patched-version claim from a roundup, including this one, without opening the release notes.

Four days earlier, the vendor blog explained that upgrades are fine now

On 2 May the same blog ran a guest piece on membership organisations, bylined to Umbraco and written by Cantarus, an Umbraco Platinum Partner — so it is a vendor publishing an implementation agency arguing for the product both of them sell. Its first myth is that upgrades are painful, and the answer is that since Umbraco 9 moved to .NET Core they have been "way more predictable and manageable".

That is true, and it is also exactly what the advisory tested four days later. Predictable is not the same as free. The teams for whom 6 May was a non-event were the ones already on the latest minor, which is a maintenance posture rather than a platform property. If the myth-busting piece is going into your next proposal, pair it with the advisory: the honest version of the argument is that Umbraco upgrades are cheap when you do them continuously and expensive when you do them once a year.

The most useful software this month came from two individuals

Rick Butterfield released ContentAudit, a package that does "first class site crawling and SEO auditing inside Umbraco" — his words, and worth noting that he is announcing something he built himself over roughly six months. It installs as Umbraco.Community.ContentAudit (1.0.0-beta at the time of writing), adds an Audit section, crawls the site, and surfaces issues such as missing headings, absent meta descriptions and orphaned pages, with the results also visible in a content app while an editor works on the page. The issue types are extensible through IAuditPageIssue and IAuditImageIssue. Butterfield is candid that a full crawl is intensive and belongs on staging first. Treat the beta label seriously and it is the closest thing Umbraco has to Screaming Frog living inside the backoffice.

Owain Williams — the harvest records his byline as the site handle Owain.Codes — published the story of building an Obsidian plugin that pushes Markdown notes into Umbraco as content. The plugin (Umbracidian) matters less than the write-up, which is one of the few honest accounts of using the Management API from outside C#. He documents the wrong turn of reaching for the Delivery API first, calls the Swagger output unhelpful unless you already know the endpoint you want, and notes that the official examples stop at fetching cultures. If you are about to automate anything against the backoffice, read it before you budget the work.

Kevin Jump shipped both halves of a uSync week. 15.1.8 is patches: editorUIAlias mapping, less aggressive JSON tidying, a default list view fix, and all XElement loads and saves forced through the file service. 16.0.0-rc is the bigger signal — it removes everything marked "obsolete, will remove in v16", moves the settings dictionary to <string, object> for usable IntelliSense in appsettings.json, and changes auth token handling. His release notes describe it as built against Umbraco 16 RC2; that is a source-repo claim about uSync and a second-hand one about Umbraco's own release schedule, so confirm the CMS side against Umbraco's release notes before you plan a date around it.

What the vendor spent the rest of the month on

Six of the fourteen Umbraco items our harvest returned for May came from umbraco.com — 43% of the month's coverage is the vendor talking about its own product and community, and you should weight this post accordingly. Of those six, one is the advisory and one is a product tutorial: part four of the personalization series, by Leon de Wildt, on segmenting by UTM parameters and traffic source in Umbraco Engage. Engage is a paid add-on, so read it as documentation for something you buy rather than as a technique you can apply to a stock install.

The remaining four are community: the 2025 Awards nominees by Pernille Stausbøll, with winners to be announced at Codegarden; a uProfile interview with Cherie Gregory of Koben Digital by Lucy Brailsford; and the 2025/2026 community sustainability team by Martin Wülser. Useful if you are picking projects to benchmark against or looking for the people to talk to about carbon budgets. Not useful if you are trying to decide what to do this week.

The month's one ecosystem item is Dennis Adolfi on Microsoft's Foundry Local, which runs open models such as Phi-3 on your own machine, exposes a REST API on localhost and needs no Azure subscription. That is not an Umbraco release and we are not pretending it is. It is relevant because Adolfi has already published a backoffice copilot built on Semantic Kernel, and local inference changes the compliance conversation around that class of work from "where does the content go" to "nowhere".

Where the record was wrong

Two entries in our harvest for the Umbraco set are Sitecore articles: Dean's Dynamics option sets in Sitecore Forms and custom dropdown lists from Dynamics, both published 7 May. The record bylines him by first name only; the source is Dean O'Brien's blog and our registry flags his employer, Northumbria University, as a commercial interest. They are good posts and they belong in a Sitecore roundup, not this one.

A third entry, a tag listing on adolfi.dev, is not an article at all. It is a category page that credits nobody, and its top entry is the Foundry Local post already cited above. We link the article, not the listing.

May is also a backfilled month for us, reached through feed archives rather than harvested live, so fourteen items is a floor rather than a census. Anything that only ever existed on social media, or on a blog that has since changed its feed, is not in here.

What we would do with this month

Two individuals shipped the software that changes what you can do with Umbraco this month, and neither of them works for Umbraco. Half of the upgrade tooling the market depends on is one person's release cadence, and it went to a v16 release candidate before the CMS it targets had shipped. That is the healthy version of an open ecosystem and it is also a concentration risk that nobody prices into a project budget.

The concrete thing to take from May 2025 is smaller and more annoying. If your patch path runs through a minor upgrade you have not done, you do not have a patch path, you have a project. Go and check which minor your production sites are on before the next advisory decides the timing for you.

Sources

umbraco · umbraco-cms · umbraco-cloud · product · community · release · seo · how-to

2026 © Umbracolombia - All rights reserved.