Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
| CVE ID | CVE-2025-2749 |
| Vendor | Kentico |
| Affected Product | Kentico Xperience |
| Vulnerability Type | Vulnerability |
| CVSS Score | 9.5 (CRITICAL) |
| Actively Exploited | ✅ Yes — CISA KEV Listed |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via cisa_kev) |
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.