CVE-2025-2749HIGH 7.2CISA KEVEPSS p88.7%
CVE-2025-2749Kentico Xperience Path Traversal Vulnerability
Kentico / Kentico Xperience
Description
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
Scoring
| CVSS 3.1 | 7.2 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.81% probability of exploitation · percentile 88.7% · 2026-06-19T12:03:05Z |
| Published | 2025-03-24 |
| Last modified | 2026-04-21 |
CISA KEV entry
Added to KEV: 2026-04-20
Underlying weaknesses· 2
References
- https://devnet.kentico.com/download/hotfixes
- https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms/
- https://www.vulncheck.com/advisories/kentico-xperience-staging-media-file-upload-authenticated-rce
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2749
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-22 | 0% | live |
| Weakness | Unrestricted Upload of File with Dangerous Typecwe-434 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Kentico Xperience Path Traversal Vulnerabilitykev-cve-2025-2749 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.