Kentico

Xperience

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 24.03.2025 18:22:30
  • Zuletzt bearbeitet 27.12.2025 17:15:47

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.

Exploit
  • EPSS 1.23%
  • Veröffentlicht 24.03.2025 18:18:07
  • Zuletzt bearbeitet 04.11.2025 23:15:34

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be ex...

Warnung Medienbericht Exploit
  • EPSS 88.93%
  • Veröffentlicht 24.03.2025 18:17:06
  • Zuletzt bearbeitet 06.11.2025 13:58:01

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative obje...

Warnung Medienbericht Exploit
  • EPSS 86.08%
  • Veröffentlicht 24.03.2025 18:16:04
  • Zuletzt bearbeitet 06.11.2025 13:58:06

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrativ...

  • EPSS 0.95%
  • Veröffentlicht 18.07.2022 17:15:09
  • Zuletzt bearbeitet 19.12.2025 20:54:33

In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 16.04.2022 00:15:09
  • Zuletzt bearbeitet 19.12.2025 20:54:25

Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Admin...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 10.01.2022 14:11:30
  • Zuletzt bearbeitet 19.12.2025 20:56:46

Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 03.12.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:10

The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client ...

  • EPSS 0.36%
  • Veröffentlicht 09.09.2020 15:15:11
  • Zuletzt bearbeitet 19.12.2025 20:48:04

Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.

Exploit
  • EPSS 0.66%
  • Veröffentlicht 02.12.2019 03:15:11
  • Zuletzt bearbeitet 19.12.2025 20:48:04

Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.