MEDIUM
Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure
Published Dec 18, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.31%
Description
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.
Affected products
-
Affected
- ≥ 0, ≤ 12.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://devnet.kentico.com/download/hotfixes vendor-advisorypatchProduct
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204356 Advisory
- https://www.vulncheck.com/advisories/kentico-xperience-portal-engine-form-control-information-disclosure third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://devnet.kentico.com/download/hotfixes | vendor-advisorypatchProduct | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204356 | Advisory | |
| https://www.vulncheck.com/advisories/kentico-xperience-portal-engine-form-control-information-disclosure | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Dec 18, 2025
Updated Dec 30, 2025
Reserved Dec 17, 2025
Link CVE-2022-50686
CISA Vulnrichment
Updated Dec 18, 2025
Red Hat
No data
GitHub
No data