<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="https://devnet.kentico.com/rss/hotfixes" rel="self" type="application/rss+xml"/>
<title><![CDATA[DevNet Hotfixes]]></title>
<link><![CDATA[https://devnet.kentico.com/rss/hotfixes]]></link>
<description><![CDATA[You can find list of available Kentico CMS hotfixes below]]></description>
<language><![CDATA[en-US]]></language>
<item>
     <title>Hotfix <![CDATA[13.0.204]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;picomatch&#39; updated to v2.3.2 - The hotfix updates the &#39;picomatch&#39; package used by Page and Form builder client scripts to version &#39;2.3.2&#39;. The updates address security vulnerabilities from previous versions.</li><li>Application dashboard - In versions 13.0.197 (Refresh 14) or newer, the welcome tile on the application dashboard could reappear after being dismissed, even though it did not display any new messages.</li><li>Continuous integration - A &quot;Could not load file or assembly&quot; error occurred when running the ContinuousIntegration.exe utility. The issue occurred only after installing hotfix 13.0.203.</li></ul>]]></description>  
     <pubDate>Thu, 02 Apr 2026 12:35:44 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_204.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.203]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;MimeKit&#39; update to v4.15.1 - The hotfix updates the &#39;MimeKit&#39; NuGet package dependency to version &#39;4.15.1&#39; to address security vulnerabilities from previous versions. As a result of the update, the &#39;MailKit&#39; NuGet package dependency was also updated to  &#39;4.15.1&#39;.</li></ul>]]></description>  
     <pubDate>Thu, 26 Mar 2026 06:31:02 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_203.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.202]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;HtmlSanitizer&#39; updated to 9.0.892 - The hotfix updates the &#39;HtmlSanitizer&#39; NuGet package dependency to version &#39;9.0.892&#39;. The update addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 19 Feb 2026 09:05:59 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_202.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.201]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;axios&#39; updated to 1.13.5 - The hotfix updates the &#39;axios&#39; package used by Page and Form builder client scripts to version &#39;1.13.5&#39;. The updates address security vulnerabilities from previous versions.</li><li>Security (Moderate) - &#39;lodash&#39; and &#39;lodash-es&#39; updated to 4.17.23 - The hotfix updates the &#39;lodash&#39; and &#39;lodash-es&#39; packages used by Page and Form builder client scripts to version &#39;4.17.23&#39;. The updates address security vulnerabilities from previous versions.</li><li>Security (Informative) - &#39;diff&#39; updated to 4.0.4 - The hotfix updates the &#39;diff&#39; package used by Page and Form builder client scripts to version &#39;4.0.4&#39;. The updates address security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 12 Feb 2026 12:06:14 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_201.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.200]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Application dashboard - The Welcome tile on the application dashboard providing the latest news about Xperience by Kentico displayed unresolved resource strings when the data source was unavailable.</li></ul>]]></description>  
     <pubDate>Thu, 05 Feb 2026 14:13:30 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_200.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.199]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;qs&#39; updated to 6.14.1 - The &#39;qs&#39; transitive dependency used by &#39;Page builder&#39; and &#39;Form builder&#39; client scripts was updated to version 6.14.1, which addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 08 Jan 2026 11:19:17 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_199.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.198]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Informative) -  &#39;express&#39; updated to 4.22.0 - The &#39;express&#39; transitive dependency of &#39;Page builder&#39; and &#39;Form builder&#39; client scripts was updated to version 4.22.0, which addresses security vulnerabilities from previous versions.</li><li>Security (Important) -  &#39;node-forge&#39; updated to 1.3.2 - The &#39;node-forge&#39; transitive dependency of &#39;Page builder&#39; and &#39;Form builder&#39; client scripts was updated to version 1.3.2, which addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 11 Dec 2025 14:01:57 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_198.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.197]]></title>
     <description><![CDATA[<p>Hotfix 13.0.197 is the Kentico Xperience 13 Refresh 14 release, which represents a larger update than a standard hotfix and includes new features. For detailed information about the introduced changes, please refer to the <a href="https://docs.xperience.io/13/release-notes-xperience-13#ReleasenotesXperience13-Ref14" target="_blank">Refresh release notes</a>.<br />
&nbsp;<br />
Be sure to check our <a href="https://docs.xperience.io/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process. It might save you some trouble afterwards.</p>
]]></description>  
     <pubDate>Thu, 04 Dec 2025 13:45:30 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_197.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.196]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Images - Image recognition failed when large images were uploaded through rich text editor fields, including those on the Content tab of the Pages application and in Rich text page builder widgets.</li></ul>]]></description>  
     <pubDate>Thu, 20 Nov 2025 11:29:08 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_196.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.195]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;microsoft.codedom.providers.dotnetcompilerplatform&#39; update to v4.1.0 - The hotfix updates the &#39;microsoft.codedom.providers.dotnetcompilerplatform&#39; package to version 4.1.0, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Thu, 16 Oct 2025 11:49:58 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_195.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.194]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Microsoft Azure - The &#39;Clean Azure storage cache&#39; scheduled task failed to clean the local Azure cache if the paths provided via the &#39;CMSAzureTempPath&#39; or &#39;CMSAzureCachePath&#39; keys used the &#39;/&#39; (forward slash) separator.</li></ul>]]></description>  
     <pubDate>Thu, 02 Oct 2025 14:01:14 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_194.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.193]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;axios&#39; update to v1.12.2 - The hotfix updates the &#39;axios&#39; third-party dependency used by the Page Builder feature to version 1.12.2, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Thu, 18 Sep 2025 11:29:50 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_193.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.192]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Pages - Saving a value in the &#39;Redirect on unpublish&#39; field on a page&#39;s Content tab did not work for projects based on Refresh 12 (version 13.0.142), which had their database recreated using the database creation wizard (e.g., when installing the database after the installation process).</li></ul>]]></description>  
     <pubDate>Thu, 11 Sep 2025 10:48:17 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_192.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.191]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - Last sign-in not tracked for external users  - The system did not update the &#39;Last sign-in&#39; value for users that signed-in to the administration UI via external authentication.</li></ul>]]></description>  
     <pubDate>Thu, 28 Aug 2025 11:30:24 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_191.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.190]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>WYSIWYG editor - When inserting links into the Rich text editor component for the page and form builder, URLs containing encoded characters (e.g., spaces encoded as `%20`) were encoded again, which could break the URL in some cases.</li></ul>]]></description>  
     <pubDate>Thu, 31 Jul 2025 12:41:36 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_190.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.189]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Critical) - &#39;form-data&#39; update to 4.0.4 - The hotfix updates the &#39;form-data&#39; third-party library to version 4.0.4, which addresses security vulnerabilities in the previous version.</li><li>Security (Informative) - &#39;on-headers&#39; update to 1.1.0 - The hotfix updates the &#39;on-headers&#39; third-party library to version 1.1.0, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Sun, 27 Jul 2025 09:00:03 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_189.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.188]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Informative) - &#39;brace-expansion&#39; dependency update - The hotfix updates the &#39;brace-expansion&#39; library used by Page and Form Builder scripts to version 1.1.12 to address security vulnerabilities.</li><li>Performance - Using content tree-based routing generated unnecessary SQL queries when &#39;URL format for multilingual sites&#39; was set to &#39;Language prefix&#39;. The database was only queried when a URL was accessed for the first time; all following requests for that same path were resolved using the cache.</li></ul>]]></description>  
     <pubDate>Thu, 19 Jun 2025 11:37:04 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_188.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.187]]></title>
     <description><![CDATA[<p>Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br />
<br />
Fixed bugs:</p>

<ul>
	<li>General - Internal infrastructure updates -&nbsp;Hotfix 13.0.187 contains internal infrastructure updates, and does not directly impact Kentico Xperience projects.</li>
</ul>
]]></description>  
     <pubDate>Thu, 29 May 2025 08:51:07 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_187.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.186]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Staging - Staging task error messages displayed by the system after hotfixing to 13.0.181 now provide more details about the source of the issue.</li></ul>]]></description>  
     <pubDate>Thu, 15 May 2025 11:01:36 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_186.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.185]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - AngularJS library update to 1.8.3 - The hotfix updates the AngularJS library used in certain parts of the administration interface to version 1.8.3. This addresses security vulnerabilities in the original 1.5.5 version.</li></ul>]]></description>  
     <pubDate>Wed, 07 May 2025 11:18:00 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_185.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.184]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - http-proxy-middleware update to 2.0.9 - The hotfix updates the http-proxy-middleware used by the administration interface to version 2.0.9, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Wed, 30 Apr 2025 12:35:40 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_184.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.183]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Staging - The new staging logic introduced as part of the authorization bypass vulnerability fix in hotfix version 13.0.178 did not reflect the &#39;CMSAcceptAllCertificates&#39; and &#39;CMSStagingAcceptAllCertificates&#39; configuration keys.</li></ul>]]></description>  
     <pubDate>Thu, 24 Apr 2025 10:53:59 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_183.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.182]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - MooTools library made obsolete - The hotfix obsoletes the outdated MooTools library bundled with the administration project to improve security, due to potential vulnerabilities. The library, located under ~/CMSScripts/mootools.js, was carried over from previous versions of Kentico Xperience and is not used by any default functionality in Kentico Xperience 13. If your custom code depends on any features from this library, we recommend referencing an external implementation.</li><li>Security (Important) - Require.js library update to v2.3.7 - The Require.js library contained a vulnerability with high severity: Prototype pollution. The hotfix addresses this security vulnerability by updating the library to version 2.3.7. </li></ul>]]></description>  
     <pubDate>Thu, 10 Apr 2025 10:02:02 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_182.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.181]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Critical) - Underscore.js library update to v1.13.7 - The Underscore.js library contained a critical vulnerability: Arbitrary Code Execution. The hotfix addresses this security vulnerability by updating the library to version 1.13.7. </li><li>Security (Moderate) - Stored XSS via media library upload - As an authenticated user, it was possible to distribute a malicious payload by abusing media library file upload and following certain specific steps. </li><li>Security (Moderate) - Froala editor update to v4.5.0 - The hotfix updates the Froala WYSIWYG editor used in the &#39;Rich text&#39; page builder widget to version 4.5.0, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Thu, 03 Apr 2025 14:22:34 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_181.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.180]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - Denial of service using Content staging - It was possible to launch a denial-of-service attack by exploiting the system&#39;s Content staging feature. Staging did not need to be enabled, the vulnerability was exploitable under all circumstances. Applying the hotfix results in a functional breaking change in the Content staging feature. See the hotfix instructions in the documentation for details and potential manual steps required after hotfixing your instance.</li></ul>]]></description>  
     <pubDate>Fri, 28 Mar 2025 16:11:05 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_180.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.179]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - Update of third-party dependencies - The hotfix updates several third-party dependencies of page and form builder scripts to newer versions that address vulnerabilities.</li><li>Security (Informative) - Self-XSS in the database installation step - It was possible to perform a Self-Cross Site Scripting attack when progressing through the &#39;additional database installation&#39; wizard in the administration project.</li></ul>]]></description>  
     <pubDate>Thu, 20 Mar 2025 12:13:18 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_179.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.178]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - SQL injection in product installer - The product database installer was vulnerable to an SQL injection attack during the installation process. To fix the issue, the hotfix must be applied to the Setup files (switch to advanced mode in the hotfix utility) as well as your instance (database installation can be triggered multiple ways).</li><li>Security (Moderate) - Stored XSS when uploading files - It was possible to distribute a malicious payload as an unauthenticated user when uploading multiple files to the application. A similar vulnerability could have also been exploited by authenticated users. Applying the hotfix introduces functional changes to the application&#39;s file retrieval endpoint for certain types of files. See the hotfix instructions for details.</li><li>Security (Critical) - Authorization bypass in content staging - Due to a vulnerability in a third-party library used by the product, the staging authentication mechanism could be bypassed. Only instances with the staging functionality enabled were affected. This vulnerability exploited a different attack vector from the one fixed in hotfix 13.0.173. See the hotfix instructions in the documentation for possible manual steps required after hotfixing your instance. If you don&#39;t use staging and want to completely mitigate all possible vulnerabilities, you can limit which external services can access the staging endpoint ‘/CMSPages/Staging/SyncServer.asmx’ by editing the &#39;&lt;location path=&quot;Staging/SyncServer.asmx&quot;&gt;&#39; node in the config file under &#39;~/CMS/CMSPages/Web.config&#39;. To deny access to all users, set &#39;authorization&#39; to &#39;&lt;deny users=&quot;*&quot; /&gt;&#39;.</li><li>Security (Important) - Post-auth remote code execution - Staging media files could lead to Remote Code Execution on the target server.</li></ul>]]></description>  
     <pubDate>Thu, 06 Mar 2025 12:50:17 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_178.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.177]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - Updated Lodash to the latest version - The Lodash JavaScript library used in the administration interface was updated to version 4.17.21 due to security vulnerabilities contained in the previously used version.</li><li>Form components - If a form&#39;s output code included the &#39;&lt;fieldset&gt;&#39; HTML tag (for example added via a custom form builder section), an error occurred when attempting to select a file in a form field using the &#39;File uploader&#39; component.</li></ul>]]></description>  
     <pubDate>Thu, 27 Feb 2025 14:17:41 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_177.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.176]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Event log - During startup, if the application failed to load a referenced assembly whose full file system path was longer than 100 characters, the application raised an unhandled event log-related exception &#39;Value cannot be longer than 100 characters. (Parameter &#39;eventCode&#39;)&#39; instead of logging the original issue. </li></ul>]]></description>  
     <pubDate>Thu, 20 Feb 2025 09:29:22 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_176.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.175]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Amazon S3 - Accessing resources hosted in Amazon S3 occassionally resulted in unhandled IO exceptions, which could, for example, cause broken links to images and other resources on the live site.</li></ul>]]></description>  
     <pubDate>Thu, 13 Feb 2025 12:45:48 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_175.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.174]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.xperience.io/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Scheduler - An error occurred when executing certain scheduled tasks (e.g., &#39;Recalculate time zone&#39;)  using the external Windows service.</li></ul>]]></description>  
     <pubDate>Thu, 06 Feb 2025 14:38:21 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_174.exe</link>    
</item></channel>
</rss>
