CVE-2025-5591

Stored Cross-site Scripting (XSS) in Kentico Xperience 13

Discovered by Michael Nervo on behalf of The Missing Link Security

Vulnerability Details

Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.

Affected Versions

Before 13.0.167

Fixed Versions

Mitigation: The Missing Link recommends changing Kentico's default configuration as per the vendor's advisory: Reference

Latest News