Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kentico
Kentico xperience |
|
| Vendors & Products |
Kentico
Kentico xperience |
Mon, 05 Jan 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context. | |
| Title | Stored Cross-site Scripting (XSS) in Kentico Xperience 13 | |
| Weaknesses | CWE-1188 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TML
Published:
Updated: 2026-01-05T20:34:18.323Z
Reserved: 2025-06-04T00:11:17.246Z
Link: CVE-2025-5591
Updated: 2026-01-05T20:34:10.485Z
Status : Received
Published: 2026-01-05T01:15:51.617
Modified: 2026-01-05T01:15:51.617
Link: CVE-2025-5591
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:13:24Z