CVE-2023-53737

A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.

medium 4.8 CVSS 3.1
Published: Dec 18, 2025
Modified: Dec 27, 2025
Vendor: Kentico
Product: Xperience

Description

A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.

References

Related CVEs