CVE-2025-5591: Kentico Xperience
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Affected products
- Kentico Xperience: from 13.0.0, before 13.0.167 (fixed in 13.0.167)
Published 2026-01-05. Last modified 2026-10-07.