VendorsKenticoxperienceall versions
Vulnerabilities

Kentico Xperience

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2025-2747
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
Published 2025-03-24 · Analyzed
9.8KEVEPSS 0.972
CVE-2019-10068
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
Published 2019-03-26 · Analyzed
9.8KEVEPSS 0.951
CVE-2025-2746
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
Published 2025-03-24 · Analyzed
9.8KEVEPSS 0.730
CVE-2017-17736
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
Published 2018-03-23 · Modified
9.8EPSS 0.685
CVE-2025-32370
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.
Published 2025-04-06 · Analyzed
9.81 PoCEPSS 0.015
CVE-2019-12102
Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs_media.aspx URI. NOTE: The vendor disputes the report because the researcher did not configure the media library permissions correctly. The vendor states that by default all users can read/modify/upload files, and it’s up to the administrator to decide who should have access to the media library and set the permissions accordingly. See the vendor documentation in the references for more information
Published 2019-05-22 · Modified
9.1EPSS 0.022
CVE-2018-7046
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout
Published 2018-02-20 · Modified
9.0EPSS 0.054
CVE-2018-19453
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
Published 2019-04-10 · Analyzed
8.8EPSS 0.014
CVE-2019-25229
Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Upload
Published 2025-12-18 · Analyzed
8.8EPSS 0.003
CVE-2021-47711
Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection
Published 2025-12-18 · Analyzed
8.8EPSS 0.003
CVE-2025-2794
Kentico Xperience <= 13.0.180 Unsafe Reflection
Published 2025-03-31 · Modified
8.7EPSS 0.005
CVE-2023-53934
Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service
Published 2025-12-18 · Analyzed
8.7EPSS 0.004
CVE-2020-36890
Kentico Xperience <= 10 Administrator Access Control Bypass
Published 2025-12-18 · Analyzed
8.6EPSS 0.003
CVE-2018-5282
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework
Published 2018-01-08 · Modified
7.81 PoCEPSS 0.015
CVE-2025-5591
Stored Cross-site Scripting (XSS) in Kentico Xperience 13
Published 2026-01-05 · Analyzed
7.7EPSS 0.002
CVE-2022-32387
In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.
Published 2022-07-18 · Analyzed
7.5EPSS 0.011
CVE-2022-50686
Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure
Published 2025-12-18 · Modified
7.5EPSS 0.003
CVE-2021-47712
Kentico Xperience <= 12.0.102 URL Hashing Cryptography Vulnerability
Published 2025-12-18 · Analyzed
7.5EPSS 0.002
CVE-2025-2749
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
Published 2025-03-24 · Analyzed
7.2KEVEPSS 0.041
CVE-2019-6242
Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vulnerability. The vendor plans to fix it at a future time
Published 2019-02-08 · Modified
7.2EPSS 0.012
CVE-2018-6843
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
Published 2018-03-19 · Modified
7.2EPSS 0.011
CVE-2024-58320
Kentico Xperience <= 13.0.159 Authentication Information Disclosure
Published 2025-12-18 · Analyzed
6.9EPSS 0.003
CVE-2022-50682
Kentico Xperience <= 13.0.79 Routing Engine CRLF Injection
Published 2025-12-18 · Analyzed
6.9EPSS 0.002
CVE-2024-58317
Kentico Xperience <= 13.0.164 Cookie Security Configuration
Published 2025-12-18 · Analyzed
6.9EPSS 0.002
CVE-2021-43991
Persistent XSS via Avatar Upload in Kentico Xperience CMS
Published 2021-12-03 · Modified
6.8EPSS 0.005
CVE-2025-32369
Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.
Published 2025-04-06 · Analyzed
6.4EPSS 0.003
CVE-2025-2748
Kentico Xperience stored cross-site scripting in multiple-file upload functionality
Published 2025-03-24 · Modified
6.1EPSS 0.606
CVE-2020-24794
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
Published 2020-09-09 · Modified
6.1EPSS 0.009
CVE-2021-46163
Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.
Published 2022-01-09 · Modified
6.1EPSS 0.008
CVE-2022-50681
Kentico Xperience <= 13.0.88 Rich Text Editor Reflected XSS
Published 2025-12-18 · Modified
6.1EPSS 0.002
CVE-2022-50684
Kentico Xperience <= 13.0.71 Form Emails HTML Injection
Published 2025-12-18 · Modified
6.1EPSS 0.002
CVE-2024-58319
Kentico Xperience <= 13.0.160 Pages Dashboard Widget Reflected XSS
Published 2025-12-18 · Modified
6.1EPSS 0.002
CVE-2024-58318
Kentico Xperience <= 13.0.162 Rich Text Editor Stored XSS
Published 2025-12-18 · Modified
6.1EPSS 0.002
CVE-2019-19493
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
Published 2019-12-02 · Modified
5.41 PoCEPSS 0.020
CVE-2018-6842
Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.
Published 2018-03-19 · Modified
5.4EPSS 0.006
CVE-2020-36891
Kentico Xperience <= 12.0.49 File Upload Stored XSS
Published 2025-12-18 · Modified
5.4EPSS 0.002
CVE-2020-36889
Kentico Xperience <= 12.0.90 Administration Interface Stored XSS
Published 2025-12-18 · Modified
5.4EPSS 0.002
CVE-2023-53738
Kentico Xperience <= 13.0.109 Page Preview Reflected XSS
Published 2025-12-18 · Modified
5.4EPSS 0.002
CVE-2023-53736
Kentico Xperience <= 13.0.120 Administration Interface Reflected XSS
Published 2025-12-18 · Modified
5.4EPSS 0.002
CVE-2024-58321
Kentico Xperience <= 13.0.159 Form Validation Stored XSS
Published 2025-12-18 · Modified
5.4EPSS 0.002
1 / 2Next →