A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.
History

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.
Title Kentico Xperience <= 12.0.90 Administration Interface Stored XSS
First Time appeared Kentico
Kentico xperience
Weaknesses CWE-79
CPEs cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Vendors & Products Kentico
Kentico xperience
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-18T21:48:24.696Z

Reserved: 2025-12-09T11:05:19.896Z

Link: CVE-2020-36889

cve-icon Vulnrichment

Updated: 2025-12-18T21:09:27.438Z

cve-icon NVD

Status : Received

Published: 2025-12-18T20:15:49.200

Modified: 2025-12-18T20:15:49.200

Link: CVE-2020-36889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.