CVE-2018-7046: Kentico Xperience

High severity, CVSS 7.2. EPSS: 5.4% chance of exploitation in the next 30 days.

Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout

Affected products

  • Kentico Xperience: from 9.0, up to and including 11.0

Published 2018-02-20. Last modified 2026-06-17.