Metrics
Affected Vendors & Products
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers. | |
| Title | Kentico Xperience <= 13.0.56 File Upload Stored XSS | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-18T19:53:29.551Z
Updated: 2025-12-27T16:57:58.016Z
Reserved: 2025-12-17T16:54:12.491Z
Link: CVE-2022-50685
Updated: 2025-12-18T21:17:49.799Z
Status : Modified
Published: 2025-12-18T20:15:50.753
Modified: 2025-12-27T17:15:41.213
Link: CVE-2022-50685
No data.