← Vulnerability feed

Vulnerability record · CVE-2025-2748 · published 24 March 2025

CVE-2025-2748: Kentico Xperience multi-file upload allows stored XSS

Kentico · Xperience

Kentico Xperience does not fully validate or filter files uploaded through its multiple-file upload functionality, allowing stored cross-site scripting. The flaw affects versions through 13.0.178 and matters because injected script persists on the server and executes in the browsers of users who view the uploaded content.

6.1 CVSS 3.1 Medium EPSS 61% · top 0.9% CWE-79 · Cross-site scriptingCWE-434 · Unrestricted file upload
6.1CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityStored XSS with no authentication required and a very high EPSS score, though exploitation requires user interaction and no KEV listing exists.

What it is

Kentico Xperience does not fully validate or filter files uploaded through its multiple-file upload functionality, allowing stored cross-site scripting. The flaw affects versions through 13.0.178 and matters because injected script persists on the server and executes in the browsers of users who view the uploaded content.

Impact

An attacker can store malicious script that runs in the context of other users' sessions, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network through the multi-file upload feature; the vector shows no privileges required (PR:N) but user interaction is required (UI:R) for the stored payload to execute.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at 0.606 (99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the Kentico Xperience hotfix from the vendor download page, upgrading beyond 13.0.178.
  • Restrict or disable multi-file upload where not operationally required.
  • Validate and sanitize uploaded file content and names server-side, and serve uploads with safe content types and headers.
  • Deploy a content security policy and output encoding to limit script execution from stored content.

Detection

  • Monitor upload endpoints for files with script-bearing content types or unusual extensions.
  • Alert on stored content containing script tags or event handlers rendered to other users.
  • Review web logs for repeated multi-file upload requests from single sources.
  • Hunt for anomalous client-side requests or session activity following uploads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-2748 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-2746Kentico Xperience Staging Sync Server authentication bypassKentico Xperience through 13.0.172 mishandles empty SHA1 usernames in digest authentication on the Staging Sync Server, allowing an attacker to bypas…KEVEPSS 73%analysed9.8CVE-2025-2747Kentico Xperience Staging Sync Server authentication bypassKentico Xperience through 13.0.178 contains an authentication bypass in the Staging Sync Server password handling when the server password type is se…KEVEPSS 97%analysed9.8CVE-2019-10068Kentico Xperience staging service header bypass leads to .NET deserialization RCEKentico Xperience fails to validate security headers on its staging service, allowing a crafted request to skip initial authentication and reach .NET…KEVEPSS 95%analysed7.2CVE-2025-2749Kentico Xperience path traversal and file upload lead to RCEKentico Xperience through 13.0.178 allows an authenticated Staging Sync Server user to upload arbitrary data to relative paths, enabling path travers…KEVEPSS 4.1%analysed9.8CVE-2025-32370Kentico xperience unrestricted file upload vulnerabilityKentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is…EPSS 1.5%9.8CVE-2017-17736Kentico CMS install page access control bypass grants adminKentico 9.0 before 9.0.51 and 10.0 before 10.0.48 exposes CMSInstall/install.aspx in a way that bypasses access control, letting a remote unauthentic…EPSS 68%analysed9.1CVE-2019-12102Kentico xperience incorrect permission assignment vulnerabilityKentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/inser…EPSS 2.2%8.8CVE-2018-19453Kentico xperience unrestricted file upload vulnerabilityKentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2025-2748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.