We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2794

Kentico Xperience Staging Unsafe Reflection Kentico Xperience



Description

An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a Denial-of-Service condition. This issue affects Xperience: through 13.0.180.

Reserved 2025-03-25 | Published 2025-03-31 | Updated 2025-03-31 | Assigner VulnCheck


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Product status

Default status
affected

Any version
affected

Credits

Piotr Bazydlo finder

watchTowr sponsor

References

devnet.kentico.com/download/hotfixes vendor-advisory patch

cve.org (CVE-2025-2794)

nvd.nist.gov (CVE-2025-2794)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2794

Support options

Helpdesk Chat, Email, Knowledgebase