Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading. | |
| Title | Kentico Xperience <= 12.0.47 Virtual Context Information Disclosure | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-27T16:47:33.276Z
Reserved: 2025-12-17T16:58:40.852Z
Link: CVE-2019-25228
Updated: 2025-12-18T21:10:15.837Z
Status : Analyzed
Published: 2025-12-18T20:15:48.693
Modified: 2025-12-24T18:17:28.110
Link: CVE-2019-25228
No data.
OpenCVE Enrichment
No data.