Vulnerabilities
Vulnerable Software
Kentico:  >> Xperience  >> 13.0.64  Security Vulnerabilities
CVE-2025-2746
Known exploited
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
CVSS Score
9.8
EPSS Score
0.874
Published
2025-03-24
CVE-2025-2747
Known exploited
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.
CVSS Score
9.8
EPSS Score
0.889
Published
2025-03-24
In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.
CVSS Score
7.5
EPSS Score
0.01
Published
2022-07-18
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).
CVSS Score
4.9
EPSS Score
0.003
Published
2022-04-16


Contact Us

Shodan ® - All rights reserved