A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in users' browsers.
History

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in users' browsers.
Title Kentico Xperience <= 13.0.162 Rich Text Editor Stored XSS
First Time appeared Kentico
Kentico xperience
Weaknesses CWE-79
CPEs cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Vendors & Products Kentico
Kentico xperience
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-18T21:19:12.777Z

Reserved: 2025-12-17T16:51:11.810Z

Link: CVE-2024-58318

cve-icon Vulnrichment

Updated: 2025-12-18T21:17:45.908Z

cve-icon NVD

Status : Received

Published: 2025-12-18T20:15:53.637

Modified: 2025-12-18T20:15:53.637

Link: CVE-2024-58318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.