CVE-2022-50680: Kentico Xperience <= 13.0.92 Email Marketing Stored XSS
Published Dec 18, 2025
·Updated
A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to execute malicious scripts that could compromise user browsers and steal sensitive information.
Affected Software
2 affected components
Kentico Xperience<=13.0.92
Kentico Xperience<=13.0.92
Event History
Dec 18, 2025
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-50680?
CVE-2022-50680 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-50680?
To fix CVE-2022-50680, users should upgrade Kentico Xperience to version 13.0.93 or later.
3
Who is affected by CVE-2022-50680?
CVE-2022-50680 affects administration users of Kentico Xperience up to version 13.0.92.
4
What type of vulnerability is CVE-2022-50680?
CVE-2022-50680 is a stored cross-site scripting (XSS) vulnerability.
5
What are the potential impacts of CVE-2022-50680?
Exploitation of CVE-2022-50680 could allow attackers to execute malicious scripts that compromise user browsers and steal sensitive information.