Vulnerabilities > Kentico > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-03-05 CVE-2021-27581 SQL Injection vulnerability in Kentico CMS 5.5
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
network
low complexity
kentico CWE-89
critical
9.8
2019-05-22 CVE-2019-12102 Incorrect Permission Assignment for Critical Resource vulnerability in Kentico
Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs_media.aspx URI.
network
low complexity
kentico CWE-732
critical
9.1
2019-03-26 CVE-2019-10068 Deserialization of Untrusted Data vulnerability in Kentico
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.
network
low complexity
kentico CWE-502
critical
9.8
2018-03-23 CVE-2017-17736 Forced Browsing vulnerability in Kentico CMS
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
network
low complexity
kentico CWE-425
critical
9.8