Vulnerabilities
Vulnerable Software
Kentico:  >> Xperience  >> 10.0.52  Security Vulnerabilities
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
CVSS Score
7.2
EPSS Score
0.012
Published
2025-03-24
CVE-2025-2746
Known exploited
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
CVSS Score
9.8
EPSS Score
0.874
Published
2025-03-24
CVE-2025-2747
Known exploited
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.
CVSS Score
9.8
EPSS Score
0.889
Published
2025-03-24
In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.
CVSS Score
7.5
EPSS Score
0.01
Published
2022-07-18
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).
CVSS Score
4.9
EPSS Score
0.003
Published
2022-04-16
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-09-09
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
CVSS Score
5.4
EPSS Score
0.007
Published
2019-12-02
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
CVSS Score
8.8
EPSS Score
0.004
Published
2019-04-10
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout
CVSS Score
7.2
EPSS Score
0.02
Published
2018-02-20
Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout
CVSS Score
4.8
EPSS Score
0.002
Published
2018-02-20


Contact Us

Shodan ® - All rights reserved