CVE-2025-32369 describes a stored Cross-Site Scripting (XSS) vulnerability in Kentico Xperience versions prior to 13.0.181, allowing authenticated users to inject malicious content through the media library's file upload feature. This medium-severity vulnerability (CVSS 5.4) requires user interaction and authenticated access, with potential impacts including limited confidentiality and integrity compromise. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.0.181CPE matchmatch criteria | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | ||
>= 0, < 13.0.181CPE match | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.