VYPR

Xperience

by Kentico

CVEs (50)

  • CVE-2020-36889MedDec 18, 2025
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the…

  • CVE-2018-6842MedMar 19, 2018
    risk 0.35cvss 5.4epss 0.01

    Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.

  • CVE-2024-58320MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially…

  • CVE-2024-58317MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially…

  • CVE-2019-25228MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder…

  • CVE-2022-29287MedApr 16, 2022
    risk 0.32cvss 4.9epss 0.01

    Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current…

  • CVE-2023-53737MedDec 18, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.

  • CVE-2022-50680MedDec 18, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to execute malicious scripts that could compromise user browsers and steal sensitive…

  • CVE-2018-7205MedFeb 20, 2018
    risk 0.31cvss 4.8epss 0.01

    Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device…

  • CVE-2019-25230MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access…

Page 3 of 3