CVE-2025-5591
- EPSS 0.03%
- Veröffentlicht 05.01.2026 00:02:51
- Zuletzt bearbeitet 22.01.2026 17:32:40
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
CVE-2024-58323
- EPSS 0.04%
- Veröffentlicht 18.12.2025 19:53:39
- Zuletzt bearbeitet 27.12.2025 17:15:46
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder.
CVE-2024-58322
- EPSS 0.04%
- Veröffentlicht 18.12.2025 19:53:39
- Zuletzt bearbeitet 27.12.2025 17:15:46
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.
CVE-2024-58321
- EPSS 0.04%
- Veröffentlicht 18.12.2025 19:53:38
- Zuletzt bearbeitet 27.12.2025 17:15:46
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browse...
CVE-2024-58320
- EPSS 0.06%
- Veröffentlicht 18.12.2025 19:53:38
- Zuletzt bearbeitet 24.12.2025 16:39:35
An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a pub...
CVE-2024-58319
- EPSS 0.04%
- Veröffentlicht 18.12.2025 19:53:37
- Zuletzt bearbeitet 27.12.2025 17:15:46
A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrat...
CVE-2024-58318
- EPSS 0.04%
- Veröffentlicht 18.12.2025 19:53:37
- Zuletzt bearbeitet 27.12.2025 17:15:46
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentia...
CVE-2024-58317
- EPSS 0.03%
- Veröffentlicht 18.12.2025 19:53:37
- Zuletzt bearbeitet 24.12.2025 16:38:56
A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireS...
CVE-2023-53934
- EPSS 0.17%
- Veröffentlicht 18.12.2025 19:53:32
- Zuletzt bearbeitet 24.12.2025 17:01:50
A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability th...
CVE-2023-53738
- EPSS 0.05%
- Veröffentlicht 18.12.2025 19:53:31
- Zuletzt bearbeitet 27.12.2025 17:15:41
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page pre...