<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="https://devnet.kentico.com/rss/hotfixes" rel="self" type="application/rss+xml"/>
<title><![CDATA[DevNet Hotfixes]]></title>
<link><![CDATA[https://devnet.kentico.com/rss/hotfixes]]></link>
<description><![CDATA[You can find list of available Kentico CMS hotfixes below]]></description>
<language><![CDATA[en-US]]></language>
<item>
     <title>Hotfix <![CDATA[13.0.210]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;axios&#39; updated to v1.16.1 - The hotfix updates the &#39;axios&#39; package used by Page and Form builder client scripts to version &#39;1.16.1&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Critical) - Form builder SQL injection - The Form builder was vulnerable to SQL injection attacks. Exploitation required authenticated access to the administration interface with permissions for editing forms. An authenticated attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially leading to application compromise.</li></ul>]]></description>  
     <pubDate>Thu, 04 Jun 2026 13:17:15 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_210.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.209]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;js-cookie&#39; updated to v3.0.7, &#39;qs&#39; updated to v6.15.2 - The hotfix updates the &#39;js-cookie&#39; package to version &#39;3.0.7&#39; and &#39;qs&#39; to version &#39;6.15.2&#39; (along with transitive dependencies &#39;body-parser&#39; to &#39;1.20.5&#39; and &#39;express&#39; to &#39;4.22.2&#39;) used by Page and Form builder client scripts. The update addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 28 May 2026 13:14:49 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_209.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.208]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Informative) - &#39;ws&#39; updated to v8.20.1 - The hotfix updates the &#39;ws&#39; package used by Page and Form builder client scripts to version &#39;8.20.1&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Moderate) - &#39;brace-expansion&#39; updated to v5.0.6 - The hotfix updates the &#39;brace-expansion&#39; package used by Page and Form builder client scripts to version &#39;5.0.6&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Moderate) - &#39;fast-uri&#39; updated to v3.1.2 - The hotfix updates the &#39;fast-uri&#39; package used by Page and Form builder client scripts to version &#39;3.1.2&#39;. The update addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 21 May 2026 13:38:36 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_208.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.207]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;axios&#39; updated to v1.15.2 - The hotfix updates the &#39;axios&#39; package used by Page and Form builder client scripts to version &#39;1.15.2&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Moderate) - &#39;uuid&#39; updated to v14.0.0 - The hotfix updates the &#39;uuid&#39; package used by Page and Form builder client scripts to version &#39;14.0.0&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Page builder - Parts of the Page Builder interface were not loading, and the feature was reporting various console errors across browsers. This issue occurred only after updating to hotfix 13.0.206.</li></ul>]]></description>  
     <pubDate>Thu, 07 May 2026 13:26:50 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_207.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.206]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;postcss&#39; updated to v8.5.12 - The hotfix updates the &#39;postcss&#39; package used by Page and Form builder client scripts to version &#39;8.5.12&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Moderate) - &#39;MailKit&#39; updated to v4.16.0 - The hotfix updates the &#39;MailKit&#39; NuGet package dependency to version &#39;4.16.0&#39; to address security vulnerabilities from previous versions.</li><li>Security (Informative) - &#39;NuGet.Packaging&#39; and &#39;NuGet.Protocol&#39; updated to v5.11.7 - The hotfix updates the &#39;NuGet.Packaging&#39; and &#39;NuGet.Protocol&#39; NuGet package dependencies to version &#39;5.11.7&#39; to address security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 30 Apr 2026 12:23:27 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_206.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.205]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;follow-redirects&#39; updated to v1.16.0 - The hotfix updates the &#39;follow-redirects&#39; package used by Page and Form builder client scripts to version &#39;1.16.0&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Informative) - &#39;axios&#39; updated to v1.15.0 - The hotfix updates the &#39;axios&#39; package used by Page and Form builder client scripts to version &#39;1.15.0&#39;. The update addresses security vulnerabilities from previous versions.</li><li>Security (Moderate) - reCAPTCHA v2 validation vulnerability - Under certain conditions, reCAPTCHA v2 validation performed by the &#39;reCAPTCHA&#39; form builder component could fail and incorrectly accept submissions. This could enable spam submissions through forms or increased load on form-based workflows.</li><li>Security (Moderate) - &#39;lodash&#39; and &#39;lodash-es&#39; updated to v4.18.1 - The hotfix updates the &#39;lodash&#39; and &#39;lodash-es&#39; packages used by Page and Form builder client scripts to version &#39;4.18.1&#39;. The updates address security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 16 Apr 2026 12:52:31 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_205.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.204]]></title>
     <description><![CDATA[<p>Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br />
<br />
Fixed bugs:</p>

<ul>
	<li>Security (Important) - &#39;picomatch&#39; updated to v2.3.2 - The hotfix updates the &#39;picomatch&#39; package used by Page and Form builder client scripts to version &#39;2.3.2&#39;. The updates address security vulnerabilities from previous versions.</li>
	<li>Application dashboard - In versions 13.0.197 (Refresh 14) or newer, the welcome tile on the application dashboard could reappear after being dismissed, even though it did not display any new messages.</li>
	<li>Continuous integration - A &quot;Could not load file or assembly&quot; error occurred when running the ContinuousIntegration.exe utility. The issue occurred only after installing hotfix 13.0.203. Hotfix 13.0.204 resolves this automatically for new installations only. Existing projects require mandatory manual steps &ndash; see the 13.0.203 section of the Hotfix instructions in the documentation.</li>
</ul>
]]></description>  
     <pubDate>Thu, 02 Apr 2026 12:35:44 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_204.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.203]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;MimeKit&#39; update to v4.15.1 - The hotfix updates the &#39;MimeKit&#39; NuGet package dependency to version &#39;4.15.1&#39; to address security vulnerabilities from previous versions. As a result of the update, the &#39;MailKit&#39; NuGet package dependency was also updated to  &#39;4.15.1&#39;.</li></ul>]]></description>  
     <pubDate>Thu, 26 Mar 2026 06:31:02 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_203.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.202]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;HtmlSanitizer&#39; updated to 9.0.892 - The hotfix updates the &#39;HtmlSanitizer&#39; NuGet package dependency to version &#39;9.0.892&#39;. The update addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 19 Feb 2026 09:05:59 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_202.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.201]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;axios&#39; updated to 1.13.5 - The hotfix updates the &#39;axios&#39; package used by Page and Form builder client scripts to version &#39;1.13.5&#39;. The updates address security vulnerabilities from previous versions.</li><li>Security (Moderate) - &#39;lodash&#39; and &#39;lodash-es&#39; updated to 4.17.23 - The hotfix updates the &#39;lodash&#39; and &#39;lodash-es&#39; packages used by Page and Form builder client scripts to version &#39;4.17.23&#39;. The updates address security vulnerabilities from previous versions.</li><li>Security (Informative) - &#39;diff&#39; updated to 4.0.4 - The hotfix updates the &#39;diff&#39; package used by Page and Form builder client scripts to version &#39;4.0.4&#39;. The updates address security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 12 Feb 2026 12:06:14 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_201.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.200]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Application dashboard - The Welcome tile on the application dashboard providing the latest news about Xperience by Kentico displayed unresolved resource strings when the data source was unavailable.</li></ul>]]></description>  
     <pubDate>Thu, 05 Feb 2026 14:13:30 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_200.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.199]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;qs&#39; updated to 6.14.1 - The &#39;qs&#39; transitive dependency used by &#39;Page builder&#39; and &#39;Form builder&#39; client scripts was updated to version 6.14.1, which addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 08 Jan 2026 11:19:17 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_199.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.198]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Informative) -  &#39;express&#39; updated to 4.22.0 - The &#39;express&#39; transitive dependency of &#39;Page builder&#39; and &#39;Form builder&#39; client scripts was updated to version 4.22.0, which addresses security vulnerabilities from previous versions.</li><li>Security (Important) -  &#39;node-forge&#39; updated to 1.3.2 - The &#39;node-forge&#39; transitive dependency of &#39;Page builder&#39; and &#39;Form builder&#39; client scripts was updated to version 1.3.2, which addresses security vulnerabilities from previous versions.</li></ul>]]></description>  
     <pubDate>Thu, 11 Dec 2025 14:01:57 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_198.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.197]]></title>
     <description><![CDATA[<p>Hotfix 13.0.197 is the Kentico Xperience 13 Refresh 14 release, which represents a larger update than a standard hotfix and includes new features. For detailed information about the introduced changes, please refer to the <a href="https://docs.xperience.io/13/release-notes-xperience-13#ReleasenotesXperience13-Ref14" target="_blank">Refresh release notes</a>.<br />
&nbsp;<br />
Be sure to check our <a href="https://docs.xperience.io/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process. It might save you some trouble afterwards.</p>
]]></description>  
     <pubDate>Thu, 04 Dec 2025 13:45:30 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_197.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.196]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Images - Image recognition failed when large images were uploaded through rich text editor fields, including those on the Content tab of the Pages application and in Rich text page builder widgets.</li></ul>]]></description>  
     <pubDate>Thu, 20 Nov 2025 11:29:08 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_196.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.195]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - &#39;microsoft.codedom.providers.dotnetcompilerplatform&#39; update to v4.1.0 - The hotfix updates the &#39;microsoft.codedom.providers.dotnetcompilerplatform&#39; package to version 4.1.0, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Thu, 16 Oct 2025 11:49:58 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_195.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.194]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Microsoft Azure - The &#39;Clean Azure storage cache&#39; scheduled task failed to clean the local Azure cache if the paths provided via the &#39;CMSAzureTempPath&#39; or &#39;CMSAzureCachePath&#39; keys used the &#39;/&#39; (forward slash) separator.</li></ul>]]></description>  
     <pubDate>Thu, 02 Oct 2025 14:01:14 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_194.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.193]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - &#39;axios&#39; update to v1.12.2 - The hotfix updates the &#39;axios&#39; third-party dependency used by the Page Builder feature to version 1.12.2, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Thu, 18 Sep 2025 11:29:50 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_193.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.192]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Pages - Saving a value in the &#39;Redirect on unpublish&#39; field on a page&#39;s Content tab did not work for projects based on Refresh 12 (version 13.0.142), which had their database recreated using the database creation wizard (e.g., when installing the database after the installation process).</li></ul>]]></description>  
     <pubDate>Thu, 11 Sep 2025 10:48:17 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_192.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.191]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - Last sign-in not tracked for external users  - The system did not update the &#39;Last sign-in&#39; value for users that signed-in to the administration UI via external authentication.</li></ul>]]></description>  
     <pubDate>Thu, 28 Aug 2025 11:30:24 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_191.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.190]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>WYSIWYG editor - When inserting links into the Rich text editor component for the page and form builder, URLs containing encoded characters (e.g., spaces encoded as `%20`) were encoded again, which could break the URL in some cases.</li></ul>]]></description>  
     <pubDate>Thu, 31 Jul 2025 12:41:36 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_190.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.189]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Critical) - &#39;form-data&#39; update to 4.0.4 - The hotfix updates the &#39;form-data&#39; third-party library to version 4.0.4, which addresses security vulnerabilities in the previous version.</li><li>Security (Informative) - &#39;on-headers&#39; update to 1.1.0 - The hotfix updates the &#39;on-headers&#39; third-party library to version 1.1.0, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Sun, 27 Jul 2025 09:00:03 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_189.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.188]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Informative) - &#39;brace-expansion&#39; dependency update - The hotfix updates the &#39;brace-expansion&#39; library used by Page and Form Builder scripts to version 1.1.12 to address security vulnerabilities.</li><li>Performance - Using content tree-based routing generated unnecessary SQL queries when &#39;URL format for multilingual sites&#39; was set to &#39;Language prefix&#39;. The database was only queried when a URL was accessed for the first time; all following requests for that same path were resolved using the cache.</li></ul>]]></description>  
     <pubDate>Thu, 19 Jun 2025 11:37:04 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_188.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.187]]></title>
     <description><![CDATA[<p>Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br />
<br />
Fixed bugs:</p>

<ul>
	<li>General - Internal infrastructure updates -&nbsp;Hotfix 13.0.187 contains internal infrastructure updates, and does not directly impact Kentico Xperience projects.</li>
</ul>
]]></description>  
     <pubDate>Thu, 29 May 2025 08:51:07 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_187.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.186]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Staging - Staging task error messages displayed by the system after hotfixing to 13.0.181 now provide more details about the source of the issue.</li></ul>]]></description>  
     <pubDate>Thu, 15 May 2025 11:01:36 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_186.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.185]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - AngularJS library update to 1.8.3 - The hotfix updates the AngularJS library used in certain parts of the administration interface to version 1.8.3. This addresses security vulnerabilities in the original 1.5.5 version.</li></ul>]]></description>  
     <pubDate>Wed, 07 May 2025 11:18:00 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_185.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.184]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Moderate) - http-proxy-middleware update to 2.0.9 - The hotfix updates the http-proxy-middleware used by the administration interface to version 2.0.9, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Wed, 30 Apr 2025 12:35:40 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_184.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.183]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Staging - The new staging logic introduced as part of the authorization bypass vulnerability fix in hotfix version 13.0.178 did not reflect the &#39;CMSAcceptAllCertificates&#39; and &#39;CMSStagingAcceptAllCertificates&#39; configuration keys.</li></ul>]]></description>  
     <pubDate>Thu, 24 Apr 2025 10:53:59 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_183.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.182]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - MooTools library made obsolete - The hotfix obsoletes the outdated MooTools library bundled with the administration project to improve security, due to potential vulnerabilities. The library, located under ~/CMSScripts/mootools.js, was carried over from previous versions of Kentico Xperience and is not used by any default functionality in Kentico Xperience 13. If your custom code depends on any features from this library, we recommend referencing an external implementation.</li><li>Security (Important) - Require.js library update to v2.3.7 - The Require.js library contained a vulnerability with high severity: Prototype pollution. The hotfix addresses this security vulnerability by updating the library to version 2.3.7. </li></ul>]]></description>  
     <pubDate>Thu, 10 Apr 2025 10:02:02 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_182.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.181]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Critical) - Underscore.js library update to v1.13.7 - The Underscore.js library contained a critical vulnerability: Arbitrary Code Execution. The hotfix addresses this security vulnerability by updating the library to version 1.13.7. </li><li>Security (Moderate) - Stored XSS via media library upload - As an authenticated user, it was possible to distribute a malicious payload by abusing media library file upload and following certain specific steps. </li><li>Security (Moderate) - Froala editor update to v4.5.0 - The hotfix updates the Froala WYSIWYG editor used in the &#39;Rich text&#39; page builder widget to version 4.5.0, which addresses security vulnerabilities in the previous version.</li></ul>]]></description>  
     <pubDate>Thu, 03 Apr 2025 14:22:34 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_181.exe</link>    
</item><item>
     <title>Hotfix <![CDATA[13.0.180]]></title>
     <description><![CDATA[Be sure to check our <a href="https://docs.kentico.com/x/aQmRBg" target="_blank">Hotfix instructions</a> before starting the hotfix process.It might save you some trouble afterwards.<br /><br />Fixed bugs:<ul><li>Security (Important) - Denial of service using Content staging - It was possible to launch a denial-of-service attack by exploiting the system&#39;s Content staging feature. Staging did not need to be enabled, the vulnerability was exploitable under all circumstances. Applying the hotfix results in a functional breaking change in the Content staging feature. See the hotfix instructions in the documentation for details and potential manual steps required after hotfixing your instance.</li></ul>]]></description>  
     <pubDate>Fri, 28 Mar 2025 16:11:05 GMT</pubDate>     
     <link>https://download.kentico.com/CMSUpgrades/Hotfix/13_0/Hotfix_13_0_180.exe</link>    
</item></channel>
</rss>
