PT-2026-1201 · Kentico · Kentico Xperience 13
Michael Nervo
·
Published
2026-01-05
·
Updated
2026-01-22
·
CVE-2025-5591
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U |
Name of the Vulnerable Software and Affected Versions
Kentico Xperience version 13
Description
Kentico Xperience 13 is susceptible to a stored cross-site scripting (XSS) attack through a form component. This allows an attacker to hijack a victim user’s session and perform actions with the victim’s permissions. The vulnerability specifically resides in the Checkbox form component of Form Builder. Successful exploitation involves injecting malicious scripts that execute in the victim’s browser.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kentico Xperience 13