Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-2749

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.8%
CVSS Severity
CVSS v3 Score 7.2
Proposed Action
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
Ransomware Campaign
Unknown
Products affected by CVE-2025-2749


Contact Us

Shodan ® - All rights reserved