CVE-2025-2749: Kentico Xperience Path Traversal Vulnerability
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
Other sources
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2749?
CVE-2025-2749 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2025-2749?
To fix CVE-2025-2749, upgrade to Kentico Xperience version 13.0.179 or later.
Who is affected by CVE-2025-2749?
CVE-2025-2749 affects all authenticated users of Kentico Xperience version 13.0.178 and earlier.
What are the consequences of CVE-2025-2749?
CVE-2025-2749 may allow attackers to upload arbitrary files and execute code on the server.
Is CVE-2025-2749 a known issue in previous Kentico versions?
Yes, CVE-2025-2749 is a known vulnerability in Kentico Xperience versions up to and including 13.0.178.