CVE-2025-5591: Stored Cross-site Scripting (XSS) in Kentico Xperience 13
Published Jan 5, 2026
·Updated
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Affected Software
2 affected components
Kentico Xperience 13
Kentico Xperience>=13.0.0<13.0.167
Remediation
Information
Change Kentico's default configuration as per the vendor's advisory:
https://docs.kentico.com/13/macro-expressions/reference-macro-methods#advanced-text-processing
Event History
Jan 5, 2026
CVE Published
via MITRE·12:02 AM
Data Sourced
via MITRE·12:02 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5591?
CVE-2025-5591 has a high severity rating due to its potential impact on user session hijacking.
2
How do I fix CVE-2025-5591?
To fix CVE-2025-5591, update Kentico Xperience to the latest version where the vulnerability is patched.
3
What type of attack does CVE-2025-5591 facilitate?
CVE-2025-5591 facilitates a stored cross-site scripting attack.
4
Which software is affected by CVE-2025-5591?
CVE-2025-5591 affects Kentico Xperience 13.
5
What can an attacker do using CVE-2025-5591?
An attacker can hijack a victim user’s session and perform actions in their security context using CVE-2025-5591.