Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Xperience — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in Xperience, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities associated with the product Xperience, focusing on specific weakness types and security tags. It collects a historical record of security advisories issued by the vendor, covering the full timeline of known defects. This collection helps you track the vendor’s disclosure patterns, understand the recurring weakness classes affecting this product, and review the complete vulnerability history. The data provides a consolidated view of past incidents, allowing for trend analysis and risk assessment without needing to search individual database entries. You can identify patterns in the types of flaws reported over time, such as memory corruption or logic errors, and see how the vendor’s response times have evolved. This aggregation supports security teams in building a contextual understanding of the product’s reliability. The entries are organized by date and severity, making it straightforward to filter by specific weakness types or time periods. By consolidating these details, the page serves as a reference point for evaluating the overall security posture of Xperience over its operational history.

Vendor: Kentico

CVE ID Title CVSS Severity Published
CVE-2026-105046 Kentico Xperience 13 管理 API 对象级授权绕过 CWE-425 4.3 Medium 2026-10-02
CVE-2024-58323 Kentico Xperience <= 13.0.158 Checkbox Form Component Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2024-58322 Kentico Xperience <= 13.0.158 Shipping Options Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2024-58321 Kentico Xperience <= 13.0.159 Form Validation Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2024-58319 Kentico Xperience <= 13.0.160 Pages Dashboard Widget Reflected XSS CWE-79 6.1 Medium 2025-12-18
CVE-2024-58318 Kentico Xperience <= 13.0.162 Rich Text Editor Stored XSS CWE-79 6.1 Medium 2025-12-18
CVE-2024-58320 Kentico Xperience <= 13.0.159 Authentication Information Disclosure CWE-497 5.3 Medium 2025-12-18
CVE-2024-58317 Kentico Xperience <= 13.0.164 Cookie Security Configuration CWE-614 5.3 Medium 2025-12-18
CVE-2023-53934 Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service CWE-97 7.5 High 2025-12-18
CVE-2023-53737 Kentico Xperience <= 13.0.101 Localization Application Stored XSS CWE-79 4.8 Medium 2025-12-18
CVE-2023-53738 Kentico Xperience <= 13.0.109 Page Preview Reflected XSS CWE-79 5.4 Medium 2025-12-18
CVE-2022-50686 Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure CWE-209 7.5 High 2025-12-18
CVE-2022-50685 Kentico Xperience <= 13.0.56 File Upload Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2023-53736 Kentico Xperience <= 13.0.120 Administration Interface Reflected XSS CWE-79 5.4 Medium 2025-12-18
CVE-2022-50683 Kentico Xperience <= 13.0.74 Form Configuration Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2022-50684 Kentico Xperience <= 13.0.71 Form Emails HTML Injection CWE-79 6.1 Medium 2025-12-18
CVE-2022-50682 Kentico Xperience <= 13.0.79 Routing Engine CRLF Injection CWE-93 6.5 Medium 2025-12-18
CVE-2022-50681 Kentico Xperience <= 13.0.88 Rich Text Editor Reflected XSS CWE-79 6.1 Medium 2025-12-18
CVE-2022-50680 Kentico Xperience <= 13.0.92 Email Marketing Stored XSS CWE-79 4.8 Medium 2025-12-18
CVE-2021-47712 Kentico Xperience <= 12.0.102 URL Hashing Cryptography Vulnerability CWE-327 7.5 High 2025-12-18
CVE-2021-47711 Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection CWE-89 8.8 High 2025-12-18
CVE-2020-36891 Kentico Xperience <= 12.0.49 File Upload Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2020-36890 Kentico Xperience <= 10 Administrator Access Control Bypass CWE-862 7.2 High 2025-12-18
CVE-2019-25230 Kentico Xperience <= 12.0.0 User Widget Information Disclosure CWE-497 4.3 Medium 2025-12-18
CVE-2020-36889 Kentico Xperience <= 12.0.90 Administration Interface Stored XSS CWE-79 5.4 Medium 2025-12-18
CVE-2019-25228 Kentico Xperience <= 12.0.47 Virtual Context Information Disclosure CWE-497 5.3 Medium 2025-12-18
CVE-2019-25229 Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Upload CWE-434 8.8 High 2025-12-18
CVE-2025-32369 Kentico Xperience 安全漏洞 CWE-79 6.4 Medium 2025-04-06
CVE-2025-32370 Kentico Xperience 安全漏洞 CWE-912 7.2 High 2025-04-06
CVE-2025-2794 Kentico Xperience <= 13.0.180 Unsafe Reflection CWE-470 7.5 - 2025-03-31

All 34 known CVE vulnerabilities affecting Xperience with full Chinese analysis, references, and POCs where available.