Unrestricted Upload of File with Dangerous Type vulnerability in Kentico Xperience Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions.
Cross-site Scripting vulnerability in Kentico Xperience Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.