CVE-2025-2748: Kentico Xperience stored cross-site scripting in multiple-file upload functionality
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2748?
The severity of CVE-2025-2748 is classified as high due to the potential for stored XSS attacks.
How do I fix CVE-2025-2748?
To fix CVE-2025-2748, update Kentico Xperience to version 13.0.179 or later where the issue is resolved.
What is the impact of CVE-2025-2748 on Kentico Xperience?
CVE-2025-2748 allows an attacker to execute arbitrary scripts in the context of users who access the affected application.
Which versions of Kentico Xperience are affected by CVE-2025-2748?
CVE-2025-2748 affects Kentico Xperience versions up to and including 13.0.178.
Is there a workaround for CVE-2025-2748?
While the recommended solution is to upgrade, proper input validation and strict file type restrictions can help mitigate the risk temporarily.