Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kentico

First CVE: Oct 21, 2015Active for: 11 yearsTotal CVEs: 53
71.0
VTI Score
TOP TARGET

Kentico is a content management and digital experience platform vendor with a focused product portfolio centered on Xperience and Kentico CMS, both widely deployed in enterprise web properties and serving as a central entry point for content authoring and management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with a moderate tendency toward confirmed in-the-wild exploitation. The exposure recurs persistently across its CMS platforms through web-facing weakness classes including cross-site scripting, unrestricted file uploads, SQL injection, authentication bypass via alternate channels, and information disclosure, reflecting both the attack surface inherent to web applications and the administrative and data-handling privileges that CMS systems expose. Defenders should treat Kentico advisories as high-priority, particularly for internet-reachable instances, and maintain current patch status given the recurring authentication and injection vulnerabilities. Current exploitation activity, severity distribution, and detailed CVE listings are shown alongside this summary.

FAUCET AI Generated
53
Total CVEs
More Total CVEs than 99% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
7.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Kentico over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2015
10 years ago
Most Recent CVE
Jan 5, 2026
200 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10068CRITICAL
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was poss
Mar 26, 20199.898YESYES
CVE-2025-2747CRITICAL
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A
Mar 24, 20259.897YESYES
CVE-2025-2746CRITICAL
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authenticat
Mar 24, 20259.894YESYES
CVE-2017-17736CRITICAL
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS A
Mar 23, 20189.878NOYES
CVE-2025-2749HIGH
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path
Mar 24, 20257.266YESNO
CVE-2025-2748MEDIUM
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentic
Mar 24, 20256.165NOYES
CVE-2025-32370CRITICAL
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProvid
Apr 6, 20259.840NOYES
CVE-2018-5282HIGH
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor dispute
Jan 8, 20187.834NOYES
CVE-2021-27581CRITICAL
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
Mar 5, 20219.830NONO
CVE-2019-19493MEDIUM
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
Dec 2, 20195.428NOYES
View all 53 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products53 CVEs
60%
26%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.9%)
Network50 (94.3%)
Unknown2 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low51 (96.2%)
High0 (0.0%)
Unknown2 (3.8%)
User Interaction
None26 (49.1%)
Unknown2 (3.8%)
Required25 (47.2%)
Privileges Required
Low18 (34.0%)
High9 (17.0%)
None24 (45.3%)
Unknown2 (3.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (53 CVEs).

CISA KEV
4 CVEs
7.5% of CVEs· 100th percentile
Metasploit
1 CVE
1.9% of CVEs· 97th percentile
Nuclei
6 CVEs
11.3% of CVEs· 96th percentile
ExploitDB
3 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kentico.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kentico — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kentico's Products

View all 4 CNAs →

Top CWEs