Stored Cross-Site Scripting Vulnerability in Kentico Xperience
CVE-2025-32369
5.4MEDIUM
What is CVE-2025-32369?
Kentico Xperience prior to version 13.0.181 contains a vulnerability that enables authenticated users to exploit the media library's file upload feature. This flaw allows the distribution of malicious content, which can lead to stored Cross-Site Scripting attacks, posing significant risks to both the application and its users.
Affected Version(s)
Xperience 0 < 13.0.181