ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2025-2749

CRITICAL Export PDF

Kentico Kentico Xperience Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

CVSS Score
9.8
CRITICAL
Published
20 Apr 2026 00:00
Modified
N/A
Vendor
Kentico
Product
Kentico Xperience
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-22 CWE-434

Affected Systems

Kentico
Kentico Xperience
Kentico
Kentico Xperience

KEV Status

Known Exploited Vulnerability