<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Kentico</title><description>Actively exploited vulnerabilities affecting Kentico products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/kentico.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-2749 — Kentico Xperience Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-2749</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-2749</guid><description>This vulnerability in Kentico Xperience allows an authenticated user to abuse the Staging Sync Server feature to write arbitrary data outside of intended directories via path traversal. In practice, this means an attacker with valid credentials could plant malicious files — such as web shells — in sensitive locations on the server, potentially leading to full system compromise. Because authentication is required, the immediate risk is somewhat contained, but insider threats or compromised accounts make this serious.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>Kentico</category><category>Kentico Xperience</category></item><item><title>CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-2746</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-2746</guid><description>This vulnerability in Kentico Xperience CMS allows an attacker to bypass authentication by using an alternate path or channel, potentially giving them unauthorized control over administrative objects within the CMS. For organizations running this platform, that means an unauthenticated attacker could manipulate content, configurations, or user data at an administrative level — without needing valid credentials. The risk is significant for any internet-facing Kentico deployment.</description><pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate><category>Kentico</category><category>Xperience CMS</category></item><item><title>CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-2747</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-2747</guid><description>This vulnerability in Kentico Xperience CMS allows an attacker to bypass authentication through an alternate path or channel, meaning they could gain unauthorized control over administrative objects without valid credentials. For organizations running this CMS, a successful exploit could let an attacker manipulate site content, configurations, or user data at an administrative level — a significant risk for any internet-facing deployment.</description><pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate><category>Kentico</category><category>Xperience CMS</category></item></channel></rss>