Home Embedded Vulns General Vulns
CVE ID Description Severity Published Type
CVE-2021-47711 A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via onl… High (8.8) 2025-12-18 General-Purpose
CVE-2020-36891 A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-… Medium (5.4) 2025-12-18 General-Purpose
CVE-2020-36890 An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user p… High (7.2) 2025-12-18 General-Purpose
CVE-2020-36889 A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error… Medium (5.4) 2025-12-18 General-Purpose
CVE-2019-25229 An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions … High (8.8) 2025-12-18 General-Purpose