CVE-2025-2878
CVSS 3.1 Score 2.4 of 10 (low)
Details
Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2025-2878 is a newly disclosed vulnerability affecting Kentico CMS versions up to 13.0.178. The issue lies in an unknown functionality of the /CMSInstall/install.aspx file in the Additional Database Installation Wizard component. Manipulation of the 'new database' argument triggers cross-site scripting (XSS), posing a remote attack risk. To mitigate this vulnerability, it is suggested to upgrade to the latest version, 13.0.179.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CMs
Affected Vendors
- Pluck -