ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36891”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36891
Published
2025-12-18
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.