VYPR
Unrated severityNVD Advisory· Published Dec 18, 2025· Updated Dec 30, 2025

Kentico Xperience <= 12.0.49 File Upload Stored XSS

CVE-2020-36891

Description

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.