MEDIUM
Kentico Xperience <= 13.0.159 Form Validation Stored XSS
Published Dec 18, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.17%
Description
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers.
Affected products
-
- Version 0StatusaffectedConstraints<=13.0.159
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://devnet.kentico.com/download/hotfixes vendor-advisorypatchProduct
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204331 Advisory
- https://www.vulncheck.com/advisories/kentico-xperience-form-validation-stored-xss third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://devnet.kentico.com/download/hotfixes | vendor-advisorypatchProduct | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204331 | Advisory | |
| https://www.vulncheck.com/advisories/kentico-xperience-form-validation-stored-xss | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Dec 18, 2025
Updated Dec 30, 2025
Reserved Dec 17, 2025
Link CVE-2024-58321
CISA Vulnrichment
Updated Dec 18, 2025
ENISA EUVD
EUVD-2025-204331 Assigner VulnCheck
Published Dec 18, 2025
Updated Dec 30, 2025
Exploited since n/a
Link EUVD-2025-204331