Description

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.

INFO

Published Date :

2025-03-24T18:22:30.734Z

Last Modified :

2025-12-27T16:47:39.767Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2748 vulnerability.

Vendors Products
Kentico
  • Xperience
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-2748.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact