CVE-2026-105046Medium· 4.3▾ SunlitKentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-36890High· 7.2An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests
CVE-2025-5591Medium· 5.4Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
CVE-2026-80275High· 8.8Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function
CVE-2026-102582Low· 2.2A flaw was found in Moodle
CVE-2026-102584Medium· 4.3A flaw was found in Moodle
CVE-2026-102583Low· 2.7A flaw was found in Moodle