📦 Xperience

by Kentico

🔍 What is Xperience?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2746

CRITICAL CVSS 9.8 Mar 24, 2025

An authentication bypass vulnerability in Kentico Xperience's Staging Sync Server allows attackers to bypass digest authentication by exploiting empty SHA1 username handling. This enables unauthorized...

CVE-2023-53934

HIGH CVSS 7.5 Dec 18, 2025

This CVE describes a denial-of-service vulnerability in Kentico Xperience's GetResource handler where improper input validation allows attackers to send specially crafted requests that can disrupt ser...

CVE-2022-50686

HIGH CVSS 7.5 Dec 18, 2025

This vulnerability in Kentico Xperience allows attackers to view detailed error messages containing sensitive stack trace information through Portal Engine form controls. This information disclosure c...

CVE-2021-47711

HIGH CVSS 8.8 Dec 18, 2025

This SQL injection vulnerability in Kentico Xperience allows authenticated editors to execute arbitrary SQL queries through online marketing macro parameters. Attackers can access, modify, or delete d...

CVE-2021-47712

HIGH CVSS 7.5 Dec 18, 2025

A cryptography vulnerability in Kentico Xperience allows attackers to manipulate URL hash values, potentially enabling unauthorized actions or data access. This affects all Kentico Xperience deploymen...

CVE-2025-32370

HIGH CVSS 7.2 Apr 6, 2025

Kentico Xperience CMS versions before 13.0.178 allow unauthenticated attackers to bypass file extension restrictions by uploading .zip files that get processed by TryZipProviderSafe, enabling them to ...

CVE-2025-2749

HIGH CVSS 7.2 Mar 24, 2025

This vulnerability allows authenticated users of Kentico Xperience's Staging Sync Server to upload arbitrary files to path-relative locations via path traversal. Attackers can upload executable conten...

CVE-2025-5591

MEDIUM CVSS 5.4 Jan 5, 2026

Kentico Xperience 13 contains a stored cross-site scripting vulnerability in a form component that allows attackers to inject malicious scripts. When exploited, this enables session hijacking where at...

CVE-2024-58321

MEDIUM CVSS 5.4 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. This enables execution of arbitrary JavaScript in ...

CVE-2024-58322

MEDIUM CVSS 5.4 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious JavaScript into shipping options configuration. This could lead to session hijacking, credential t...

CVE-2024-58323

MEDIUM CVSS 5.4 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This enables script execution in users' browsers when the...

CVE-2024-58317

MEDIUM CVSS 5.3 Dec 18, 2025

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. This could allow session hijacking or...

CVE-2024-58318

MEDIUM CVSS 6.1 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts through the rich text editor component. This could enable attackers to execute arbitrary J...

CVE-2024-58319

MEDIUM CVSS 6.1 Dec 18, 2025

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. This could enable attackers to exe...

CVE-2024-58320

MEDIUM CVSS 5.3 Dec 18, 2025

An information disclosure vulnerability in Kentico Xperience allows unauthenticated attackers to access sensitive administration interface hostname details through a public authentication endpoint. Th...

CVE-2023-53736

MEDIUM CVSS 5.4 Dec 18, 2025

This reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts into the administration interface. Attackers can execute arbitrary scripts...

CVE-2023-53737

MEDIUM CVSS 4.8 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious scripts via the Localization application. This affects Kentico Xperience installations...

CVE-2023-53738

MEDIUM CVSS 5.4 Dec 18, 2025

This reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated attackers to inject malicious scripts via page preview URLs. When exploited, it enables execution of arbitra...

CVE-2022-50681

MEDIUM CVSS 6.1 Dec 18, 2025

CVE-2022-50681 is a reflected cross-site scripting vulnerability in Kentico Xperience's Rich Text Editor component that allows attackers to inject malicious scripts via administration input fields. Th...

CVE-2022-50682

MEDIUM CVSS 6.5 Dec 18, 2025

A CRLF injection vulnerability in Kentico Xperience's routing engine allows attackers to manipulate URL query string redirects through improper encoding. This enables header injection attacks that cou...

CVE-2022-50683

MEDIUM CVSS 5.4 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration settings. This enables execution of arbitrary JavaScri...

CVE-2022-50684

MEDIUM CVSS 6.1 Dec 18, 2025

This HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML content into form submission emails by submitting unencoded values in form fields. When administrators ...

CVE-2022-50685

MEDIUM CVSS 5.4 Dec 18, 2025

This stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to upload malicious XML files as page attachments or metafiles, which then execute malicious scripts in o...

CVE-2022-50680

MEDIUM CVSS 4.8 Dec 18, 2025

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated administration users to inject malicious scripts into email marketing templates. When these templates are rendered...

CVE-2025-2748

MEDIUM CVSS 6.1 Mar 24, 2025

Kentico Xperience has a stored cross-site scripting (XSS) vulnerability in its multiple-file upload functionality that allows attackers to upload malicious files containing JavaScript. When other user...