Confidence
Medium. Based on 30+ public sources; many snippets truncated and no public pricing numbers found.
Pricing
Quote-based (not public)
Xperience by Kentico
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Sources & method
Analyzed 9/30/2026 - 10 sources - Four CVEs disclosed in 2025, including an auth bypass reported exploited in the wild; version currency and fast patching are essential.
official x1review x4security x3news x2
- CVE-2025-2746 / CVE-2025-2747 — authentication bypass, Kentico Xperience staging service auth bypass; reported exploited in the wild.
- CVE-2025-2748 — XSS to RCE, Custom file handlers allowed XSS escalation to remote code execution.
- CVE-2025-2794 — denial of service, DoS vulnerability disclosed in Kentico Xperience.
- Legacy version exposure, Unsupported Kentico versions flagged as an ongoing security risk.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.