CVE-2019-19493: Kentico Xperience
Medium severity, CVSS 5.4. EPSS: 2% chance of exploitation in the next 30 days.
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
Affected products
- Kentico Xperience: from 9.0, before 12.0.50 (fixed in 12.0.50)
Published 2019-12-02. Last modified 2026-06-17.