---
title: Security advisory 2025-03-24
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

## Account lockout causes temporary lockout of valid users

**CVSS**: 6.9\
**Affected versions**: 29.7.0 - 30.2.2\
**Category**: Denial of service

### Summary

An issue with the [account lockout](https://docs.kentico.com/documentation/developers-and-admins/configuration/users/user-management.md#account-lockout) feature could affect access for administration users under certain conditions. As a result, valid users could experience issues with unexpected sign-out and become temporarily locked out of the system on projects with the account lockout feature enabled.

### How to fix

Update to the latest version. See [Update Xperience by Kentico projects](https://docs.kentico.com/documentation/developers-and-admins/installation/update-xperience-by-kentico-projects.md) for detailed instructions.
