Vulnerability record · CVE-2025-2748 · published 24 March 2025
CVE-2025-2748: Kentico Xperience multi-file upload allows stored XSS
Kentico · Xperience
Kentico Xperience does not fully validate or filter files uploaded through its multiple-file upload functionality, allowing stored cross-site scripting. The flaw affects versions through 13.0.178 and matters because injected script persists on the server and executes in the browsers of users who view the uploaded content.
Description
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityStored XSS with no authentication required and a very high EPSS score, though exploitation requires user interaction and no KEV listing exists.
What it is
Kentico Xperience does not fully validate or filter files uploaded through its multiple-file upload functionality, allowing stored cross-site scripting. The flaw affects versions through 13.0.178 and matters because injected script persists on the server and executes in the browsers of users who view the uploaded content.
Impact
An attacker can store malicious script that runs in the context of other users' sessions, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the multi-file upload feature; the vector shows no privileges required (PR:N) but user interaction is required (UI:R) for the stored payload to execute.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at 0.606 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Kentico Xperience hotfix from the vendor download page, upgrading beyond 13.0.178.
- Restrict or disable multi-file upload where not operationally required.
- Validate and sanitize uploaded file content and names server-side, and serve uploads with safe content types and headers.
- Deploy a content security policy and output encoding to limit script execution from stored content.
Detection
- Monitor upload endpoints for files with script-bearing content types or unusual extensions.
- Alert on stored content containing script tags or event handlers rendered to other users.
- Review web logs for repeated multi-file upload requests from single sources.
- Hunt for anomalous client-side requests or session activity following uploads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://devnet.kentico.com/download/hotfixes | Patch |
Track CVE-2025-2748 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-2748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.