A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2025-2749

Kentico Xperience Path Traversal Vulnerability

Published
2026-04-20
Modified
2026-07-31
Sources
cisa-kev

Summary

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.