Kentico Xperience Stored Cross-Site Scripting Vulnerability in Shipping Options Configuration

Vulnerability

A stored cross-site scripting vulnerability exists in Kentico Xperience versions through 13.0.158. This vulnerability allows attackers to inject malicious scripts into the shipping options configuration, which could be executed in the browsers of users, potentially leading to the theft of sensitive data.

Impact

Exploitation of this vulnerability could result in stored cross-site scripting, where injected scripts are executed in the context of the user.

Remediation

Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found on the Kentico Xperience documentation website.

Added: Dec 18, 2025, 8:19 PM
Updated: Dec 18, 2025, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
3.5
exploitability
5.2
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.