Metrics
Affected Vendors & Products
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers. | |
| Title | Kentico Xperience <= 13.0.158 Shipping Options Stored XSS | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-18T19:53:39.280Z
Updated: 2025-12-27T16:58:03.718Z
Reserved: 2025-12-17T16:51:11.810Z
Link: CVE-2024-58322
Updated: 2025-12-18T21:17:41.462Z
Status : Modified
Published: 2025-12-18T20:15:54.233
Modified: 2025-12-27T17:15:46.630
Link: CVE-2024-58322
No data.