Skip to content
COOEY

EXPOSURES › CVE-2025-2749

CVE-2025-2749

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-2749 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildsupply-chainunpatched

Kentico Xperience allows authenticated users to upload arbitrary files via path traversal, enabling data exfiltration or system compromise.

This path traversal flaw in Kentico Xperience's Staging Sync Server permits authenticated users to write files to arbitrary locations, creating a supply-chain risk for DIB vendors relying on Kentico CMS. While not an RCE, the ability to upload files to sensitive directories could facilitate privilege escalation or data exfiltration, requiring immediate patching and vendor assessment.

Shame score — A known path traversal vulnerability in a widely-used CMS product that allows authenticated users to upload arbitrary files, posing a moderate supply-chain risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.