Skip to content
COOEY

FAIL › dossier

Kentico

VENDOR

· dossier confidence 50%

Kentico has a history of high-severity vulnerabilities, including unpatched authentication bypass and remote code execution vulnerabilities, which suggests a need for improved security practices.

PROFILE
CategoryContent Management SystemWhat they doKentico is a web content management system and digital experience platform that provides a comprehensive set of tools for creating, managing, and optimizing digital experiences.
SECURITY POSTURE

The company has faced multiple high-severity vulnerabilities, indicating a potential lack of robust security practices.

Notable failures
  • CVE-2025-2746: Unpatched authentication bypass vulnerability exploited in the wild
  • CVE-2025-2747: Unpatched authentication bypass vulnerability actively exploited in the wild
  • CVE-2019-10068: Failure to validate security headers leading to unauthenticated remote code execution
  • CVE-2025-2749: Authenticated users can upload arbitrary files enabling data exfiltration or system compromise
Patterns: Repeated unpatched vulnerabilities; Lack of validation of security headers; Abuse of file upload functionality
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2019-10068 high Kentico Xperience suffered an unpatched deserialization vulnerability enabling unauthenticated remote code execution, now on CISA's KEV list.
2025-10-20 CVE-2025-2746 high Kentico Xperience CMS had an unpatched authentication bypass vulnerability exploited in the wild
2025-10-20 CVE-2025-2747 high Kentico Xperience CMS had an unpatched authentication bypass vulnerability actively exploited in the wild
2026-04-20 CVE-2025-2749 high Kentico Xperience allows authenticated users to upload arbitrary files via path traversal, enabling data exfiltration or system compromise.
Open questions: Why have there been multiple unpatched vulnerabilities? · What improvements has the company made to its security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:43:40.445728+00:00