CVE-2025-32369 MEDIUM

CVE-2025-32369

Vendor Kentico
Product Xperience
Weakness CWE-79 · XSS
Published April 6, 2025
Last update April 7, 2025

CVSS base score

6.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.

Key dates

02Disclosure timeline

April 6, 2025 CVE published
April 7, 2025 Record updated