FAIL › dossier
Kentico
VENDOR· dossier confidence 50%
Kentico has a history of high-severity vulnerabilities, including unpatched authentication bypass and remote code execution vulnerabilities, which suggests a need for improved security practices.
PROFILE
CategoryContent Management SystemWhat they doKentico is a web content management system and digital experience platform that provides a comprehensive set of tools for creating, managing, and optimizing digital experiences.
SECURITY POSTURE
The company has faced multiple high-severity vulnerabilities, indicating a potential lack of robust security practices.
Notable failures
- CVE-2025-2746: Unpatched authentication bypass vulnerability exploited in the wild
- CVE-2025-2747: Unpatched authentication bypass vulnerability actively exploited in the wild
- CVE-2019-10068: Failure to validate security headers leading to unauthenticated remote code execution
- CVE-2025-2749: Authenticated users can upload arbitrary files enabling data exfiltration or system compromise
Patterns: Repeated unpatched vulnerabilities; Lack of validation of security headers; Abuse of file upload functionality
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2019-10068 | high | Kentico Xperience suffered an unpatched deserialization vulnerability enabling unauthenticated remote code execution, now on CISA's KEV list. |
| 2025-10-20 | CVE-2025-2746 | high | Kentico Xperience CMS had an unpatched authentication bypass vulnerability exploited in the wild |
| 2025-10-20 | CVE-2025-2747 | high | Kentico Xperience CMS had an unpatched authentication bypass vulnerability actively exploited in the wild |
| 2026-04-20 | CVE-2025-2749 | high | Kentico Xperience allows authenticated users to upload arbitrary files via path traversal, enabling data exfiltration or system compromise. |
Open questions: Why have there been multiple unpatched vulnerabilities? · What improvements has the company made to its security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:43:40.445728+00:00