Kentico Xperience Unrestricted File Upload Vulnerability in MVC Forms

Vulnerability

A vulnerability allowing unrestricted file uploads has been identified in Kentico Xperience versions through 12.0.29. This issue allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can exploit this vulnerability by manipulating file names to upload potentially malicious files, leading to unauthorized file uploads on the system.

Impact

Exploitation of this vulnerability could result in unauthorized file uploads, potentially allowing for the execution of malicious files on the server.

Remediation

Users can upgrade to Kentico Xperience version 13.0.198 or later, where this vulnerability has been addressed. Instructions for applying the hotfix are available on the Kentico Xperience documentation site.

Added: Dec 18, 2025, 8:47 PM
Updated: Dec 18, 2025, 8:47 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
5.4
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.