Kentico Xperience Stored Cross-Site Scripting Vulnerability in Rich Text Editor Component

Vulnerability

A stored cross-site scripting vulnerability has been identified in Kentico Xperience versions through 13.0.162. This vulnerability allows attackers to inject malicious scripts via the rich text editor component used in page and form builders. Exploitation involves entering harmful URIs, which could enable the execution of malicious scripts in the browsers of users.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Remediation

Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.

Added: Dec 18, 2025, 8:22 PM
Updated: Dec 18, 2025, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
5.2
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.