<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
<channel>
    <title>
    <![CDATA[ Xperience by Kentico - Security updates ]]>
    </title>
    <description>
    <![CDATA[ Notifications about security updates for Xperience by Kentico. ]]>
    </description>
    <link>https://docs.kentico.com</link>
    <generator>Custom generator</generator>
    <lastBuildDate>Fri, 10 Apr 2026 09:05:34 GMT</lastBuildDate>
    <atom:link href="https://docs.kentico.com/feeds/xbyk-security.xml" rel="self" type="application/rss+xml"/>
    <language>
    <![CDATA[ en-us ]]>
    </language>
    
    <item>
        <title>
        <![CDATA[ Security advisory (April 9, 2026) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - CAPTCHA bypass vulnerability in reCAPTCHA v2 validation</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2026-04-09</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2026-04-09_xp</guid>
        <pubDate>Thu, 09 Apr 2026 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (February 23, 2026) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>None - Third‑party dependency update – Microsoft.SemanticKernel.Core</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2026-02-23</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2026-02-23_xp</guid>
        <pubDate>Mon, 23 Feb 2026 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (November 13, 2025) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>High - Timing attack vulnerability in content sync authentication</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2025-11-13</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2025-11-13_xp</guid>
        <pubDate>Thu, 13 Nov 2025 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (October 16, 2025) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Critical - Recommendation on .NET Framework Update – CVE-2025-55315</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2025-10-16</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2025-10-16_xp</guid>
        <pubDate>Thu, 16 Oct 2025 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (August 28, 2025) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>High - Magick.NET dependency update to 14.8.1</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2025-08-28</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2025-08-28_xp</guid>
        <pubDate>Thu, 28 Aug 2025 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (March 27, 2025) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - SQL Injection in kentico-xperience-dbmanager tool</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2025-03-27</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2025-03-27_xp</guid>
        <pubDate>Thu, 27 Mar 2025 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (March 24, 2025) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - Account lockout causes temporary lockout of valid users</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2025-03-24</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2025-03-24_xp</guid>
        <pubDate>Mon, 24 Mar 2025 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (January 9, 2025) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - Broken access control between contact groups and recipient lists</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2025-01-09</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2025-01-09_xp</guid>
        <pubDate>Thu, 09 Jan 2025 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (December 5, 2024) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - Reflected cross-site scripting (XSS) attack via logger endpoint</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2024-12-05</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2024-12-05_xp</guid>
        <pubDate>Thu, 05 Dec 2024 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (November 21, 2024) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - Insecure direct object reference (IDOR) in Form Builder</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2024-11-21</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2024-11-21_xp</guid>
        <pubDate>Thu, 21 Nov 2024 14:00:00 GMT</pubDate>
    </item>

    <item>
        <title>
        <![CDATA[ Security advisory (November 14, 2024) ]]>
        </title>
        <description>
        <![CDATA[ <p>A new Security Advisory was issued for Xperience by Kentico. The advisory addresses the following issues:</p> <ul><li>Medium - Self-cross-site scripting (XSS) attack via Rich text editor</li></ul> ]]>
        </description>
        <link>https://docs.kentico.com/documentation/security-advisories/security-advisory-2024-11-14</link>
        <guid isPermaLink="true">https://docs.kentico.com/x/security_advisory_2024-11-14_xp</guid>
        <pubDate>Thu, 14 Nov 2024 14:00:00 GMT</pubDate>
    </item>

</channel>
</rss>