Kentico is a content management and digital experience platform vendor with a focused product portfolio centered on Xperience and Kentico CMS, both widely deployed in enterprise web properties and serving as a central entry point for content authoring and management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with a moderate tendency toward confirmed in-the-wild exploitation. The exposure recurs persistently across its CMS platforms through web-facing weakness classes including cross-site scripting, unrestricted file uploads, SQL injection, authentication bypass via alternate channels, and information disclosure, reflecting both the attack surface inherent to web applications and the administrative and data-handling privileges that CMS systems expose. Defenders should treat Kentico advisories as high-priority, particularly for internet-reachable instances, and maintain current patch status given the recurring authentication and injection vulnerabilities. Current exploitation activity, severity distribution, and detailed CVE listings are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kentico over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10068CRITICAL An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was poss | Mar 26, 2019 | 9.8 | 98 | YES | YES |
CVE-2025-2747CRITICAL An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A | Mar 24, 2025 | 9.8 | 97 | YES | YES |
CVE-2025-2746CRITICAL An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authenticat | Mar 24, 2025 | 9.8 | 94 | YES | YES |
CVE-2017-17736CRITICAL Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS A | Mar 23, 2018 | 9.8 | 78 | NO | YES |
CVE-2025-2749HIGH An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path | Mar 24, 2025 | 7.2 | 66 | YES | NO |
CVE-2025-2748MEDIUM The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentic | Mar 24, 2025 | 6.1 | 65 | NO | YES |
CVE-2025-32370CRITICAL Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProvid | Apr 6, 2025 | 9.8 | 40 | NO | YES |
CVE-2018-5282HIGH Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor dispute | Jan 8, 2018 | 7.8 | 34 | NO | YES |
CVE-2021-27581CRITICAL The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter. | Mar 5, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-19493MEDIUM Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. | Dec 2, 2019 | 5.4 | 28 | NO | YES |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kentico.
Media articles that mention a CVE ID that affects a product developed by Kentico — matched by CVE ID, not by vendor name.