Kentico Xperience Information Disclosure Vulnerability via HTTP Referer Header

Vulnerability

A vulnerability allowing information disclosure has been identified in Kentico Xperience versions through 12.0.47. This vulnerability allows attackers to leak sensitive virtual context URLs via the HTTP Referer header when users interact with third-party domains. The exposed information can be accessed by external domains through page builder interactions and the loading of links or images.

Impact

Exploitation of this vulnerability could lead to unauthorized exposure of sensitive virtual context information to external domains.

Remediation

Users can upgrade to Kentico Xperience version 13.0.198 or later, where this vulnerability has been addressed. Instructions for applying the hotfix are available on the Kentico Xperience DevNet.

Added: Dec 18, 2025, 8:58 PM
Updated: Dec 18, 2025, 8:58 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
6.5
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.