CVE-2019-25228: Kentico Xperience <= 12.0.47 Virtual Context Information Disclosure
Published Dec 18, 2025
·Updated
An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.
Affected Software
2 affected components
Kentico Xperience<=12.0.47
Kentico Xperience<=12.0.47
Event History
Dec 18, 2025
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-25228?
CVE-2019-25228 has been categorized as an information disclosure vulnerability.
2
How do I fix CVE-2019-25228?
To remediate CVE-2019-25228, upgrade Kentico Xperience to version 12.0.48 or later.
3
What does CVE-2019-25228 affect?
CVE-2019-25228 affects Kentico Xperience versions up to and including 12.0.47.
4
What type of vulnerability is CVE-2019-25228?
CVE-2019-25228 is classified as an information disclosure vulnerability.
5
How can CVE-2019-25228 be exploited?
CVE-2019-25228 can be exploited through the HTTP Referer header when users interact with third-party domains.