CVE-2025-2748
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functio
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.
MEDIUM · CVSS 6.1
EPSS 0.00544
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0