CVE-2023-53738
Kentico Xperience <= 13.0.109 Page Preview Reflected XSS
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
18 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Kentico · XperienceWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →