← Back to CVE List
Vulnerability Intelligence Report
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE

CVE-2025-2749

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.2
HIGH
Exploitability:1.3
Impact Score:5.9
EPSS Probability:3.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-434 ↗CWE-434 Unrestricted Upload of File with Dangerous Type

Affected Products & Versions

Vendor Product Affected Versions
Kentico Xperience 0 <= 13.0.178 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
3.809%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2025-03-24T16:39:22
Published2025-03-24T18:18:07
Last Updated2026-04-21T03:55:36

LINK COPIED TO CLIPBOARD