Vendor

Kentico

As of , 4 Kentico vulnerabilities are on CISA's list of exploited vulnerabilities; 1 was added in 2026. Patch first: CVE-2019-10068.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2019-10068Deserialization of Untrusted DataKentico XperiencePatch this weekMetasploit module; EPSS 0.950.95
2CVE-2025-2746Authentication Bypass Using an Alternate Path or ChannelKentico Xperience CMSPatch this weekEPSS 0.730.73
3CVE-2025-2747Authentication Bypass Using an Alternate Path or ChannelKentico Xperience CMSPatch this weekEPSS 0.970.97
4CVE-2025-2749Path TraversalKentico Kentico XperiencePatch soon0.04

Products

  • Xperience CMS2 entries
  • Kentico Xperience1 entry
  • Xperience1 entry

Added each year

0.511.522022: 1120222023: nonenone20232024: nonenone20242025: 2220252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20221
2023none
2024none
20252
20261

Used in ransomware