Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.

Project Subscriptions

Vendors Products
Kentico Subscribe
Xperience Subscribe
Advisories

No advisories yet.

Fixes

Solution

Change Kentico's default configuration as per the vendor's advisory: https://docs.kentico.com/13/macro-expressions/reference-macro-methods#advanced-text-processing


Workaround

No workaround given by the vendor.

History

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 06 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Kentico
Kentico xperience
Vendors & Products Kentico
Kentico xperience

Mon, 05 Jan 2026 00:45:00 +0000

Type Values Removed Values Added
Description Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Title Stored Cross-site Scripting (XSS) in Kentico Xperience 13
Weaknesses CWE-1188
CWE-79
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2026-01-05T20:34:18.323Z

Reserved: 2025-06-04T00:11:17.246Z

Link: CVE-2025-5591

cve-icon Vulnrichment

Updated: 2026-01-05T20:34:10.485Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-05T01:15:51.617

Modified: 2026-01-22T17:32:40.177

Link: CVE-2025-5591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-05T10:13:24Z

Weaknesses