Kentico Xperience Information Disclosure Vulnerability in User Widget

Vulnerability

A vulnerability allowing information disclosure exists in Kentico Xperience versions through 12.0.0. This issue allows authenticated users to access sensitive system objects via the live site widget properties dialog. The vulnerability arises from inadequate access controls, enabling unauthorized access to system information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system information.

Remediation

Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.

Added: Dec 18, 2025, 8:46 PM
Updated: Dec 18, 2025, 8:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.