CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-2746

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-03-24
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

Affected Platforms (CPE)

📦
Kentico

Xperience

<= 13.0.172

References & Advisories

関連する脆弱性情報