Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-2747 KEVEPSS 92% An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for … Xperience after 13.0.178 Fix from $2,3002025-03-24 HIGH 7.5 CVE-2022-32387 In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler. Xperience 13.0.66+ Fix from $1,9502022-07-18 MEDIUM 6.1 CVE-2021-46163 Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem. Xperience No fix yet Fix from $1,6002022-01-10 MEDIUM 5.4 CVE-2021-43991 The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Seco… Xperience after 13.0.43 Fix from $1,6002021-12-03 CRITICAL 9.8 CVE-2021-27581 The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter. Kentico Cms Mitigation only Fix from $2,3002021-03-05 MEDIUM 6.1 CVE-2020-24794 Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75. Xperience 12.0.75+ Fix from $1,6002020-09-09 MEDIUM 5.4 CVE-2019-19493 Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. Xperience 12.0.50+ Fix from $1,6002019-12-02 CRITICAL 9.1 CVE-2019-12102 Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/inser… Xperience after 12.0 Fix from $2,3002019-05-22 HIGH 8.8 CVE-2018-19453 Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type. Xperience 11.0.45+ Fix from $1,9502019-04-10 CRITICAL 9.8 CVE-2019-10068 KEVEPSS 96% An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validat… Xperience 10.0.52 / 11.0.48+ Fix from $2,3002019-03-26 HIGH 7.2 CVE-2019-6242 Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor cons… Xperience No fix yet Fix from $1,9502019-02-08 CRITICAL 9.8 CVE-2017-17736EPSS 69% Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx a… Xperience 9.0.51 / 10.0.48+ Fix from $2,3002018-03-23 HIGH 7.2 CVE-2018-6843 Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface. Xperience 10.0.50 / 11.0.3+ Fix from $1,9502018-03-19 MEDIUM 5.4 CVE-2018-6842 Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page. Xperience 10.0.50 / 11.0.3+ Fix from $1,6002018-03-19 HIGH 7.2 CVE-2018-7046EPSS 5% Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a … Xperience after 11.0 Fix from $1,9502018-02-20 HIGH 7.8 CVE-2018-5282 Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML doc… Xperience after 11.0 Fix from $1,9502018-01-08 MEDIUM 5.8 CVE-2015-7823EPSS 5% Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web … Kentico Cms No fix yet Fix from $1,6002015-10-21 MEDIUM 5.0 CVE-2015-7822 Multiple cross-site scripting (XSS) vulnerabilities in Kentico CMS 8.2 allow remote attackers to inject arbitrary web script or HTML via a (1) parame… Kentico Cms No fix yet Fix from $1,6002015-10-21