Kentico
14 known vulnerabilities
Top Products
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/for
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuratio
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visit
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a syst
Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote a
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary op
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie
Frequently Asked Questions
How many CVEs affect Kentico?
Kentico has 14 CVE records in our database, including 3 critical and 5 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Kentico vulnerabilities?
Kentico has 3 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Kentico vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Kentico products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Kentico Vulnerabilities
CyberStrike scans your infrastructure for Kentico vulnerabilities and provides real-time remediation guidance.
Get Started