A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to execute malicious scripts that could compromise user browsers and steal sensitive information.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to execute malicious scripts that could compromise user browsers and steal sensitive information. | |
| Title | Kentico Xperience <= 13.0.92 Email Marketing Stored XSS | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-18T19:53:27.435Z
Updated: 2025-12-18T21:47:54.940Z
Reserved: 2025-12-17T16:54:12.491Z
Link: CVE-2022-50680
Updated: 2025-12-18T21:08:15.976Z
Status : Received
Published: 2025-12-18T20:15:49.980
Modified: 2025-12-18T20:15:49.980
Link: CVE-2022-50680
No data.