CVE-2023-53736

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/12/2025
Last modified:
27/12/2025

Description

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* 13.0.120 (including)