CVE-2019-19493: Kentico Xperience

Medium severity, CVSS 5.4. EPSS: 2% chance of exploitation in the next 30 days.

Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.

Affected products

  • Kentico Xperience: from 9.0, before 12.0.50 (fixed in 12.0.50)

Published 2019-12-02. Last modified 2026-06-17.