VYPR

Vendor CVEs

Kentico

All CVEs

55 total · sorted by risk
  • CVE-2018-7205MedFeb 20, 2018
    risk 0.31cvss 4.8epss 0.01

    Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device…

  • CVE-2019-25230MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access…

  • CVE-2025-2878LowMar 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the…

  • CVE-2015-7823Oct 21, 2015
    risk 0.00cvss epss 0.05

    Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter.

  • CVE-2015-7822Oct 21, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Kentico CMS 8.2 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter name to CMSModules/AdminControls/Pages/UIPage.aspx or the (2) CMSBodyClass cookie variable to the default URI.

Page 2 of 2